| [ LiB ] |
The following is a step-by-step discussion of the Practical Exercise solution.
IKE uses UDP port 500. The IPSec ESP and AH protocols use protocol numbers 50 and 51. You must ensure that any existing access lists you might already have configured do not block protocol 50, 51, and UDP port 500 traffic at any interface used by IPSec. In some cases you might need to reconfigure an existing access list to explicitly permit this traffic.
R1(config)#crypto isakmp policy 1 R1(config-isakmp)#authentication pre-share
R1(config)#crypto isakmp key cisco170 address 100.133.123.2 R1(config)#crypto isakmp key cisco180 address 100.133.123.3 R1(config)#crypto isakmp key cisco190 address 100.133.123.4
R2(config)#crypto isakmp policy 1 R2(config-isakmp)#authentication pre-share
R2(config)#crypto isakmp key cisco170 address 100.133.123.1
R3(config)#crypto isakmp policy 1 R3(config-isakmp)#authentication pre-share
R3(config)#crypto isakmp key cisco180 address 100.133.123.1
R4(config)#crypto isakmp policy 1 R4(config-isakmp)#authentication pre-share
R4(config)#crypto isakmp key cisco190 address 100.133.123.1
R1(config)#ip route 170.170.170.0 255.255.255.0 100.133.123.2 R1(config)#ip route 180.180.180.0 255.255.255.0 100.133.123.3 R1(config)#ip route 190.190.190.0 255.255.255.0 100.133.123.4
R1(config)#access-list 170 permit ip 160.160.160.0 0.0.0.255 170.170.170.0 0.0.0.255 R1(config)#access-list 180 permit ip 160.160.160.0 0.0.0.255 180.180.180.0 0.0.0.255 R1(config)#access-list 180 permit ip 160.160.160.0 0.0.0.255 190.190.190.0 0.0.0.255
R1(config)#crypto ipsec transform-set 170cisco esp-des esp-md5-hmac R1(cfg-crypto-trans)#exit R1(config)#crypto ipsec transform-set 180cisco esp-des esp-md5-hmac R1(cfg-crypto-trans)#exit R1(config)#crypto ipsec transform-set 190cisco esp-des esp-md5-hmac
R1(config)#crypto map mymap 17 ipsec-isakmp R1(config-crypto-m)#set peer 100.133.123.2 R1(config-crypto-m)#set transform-set 170cisco R1(config-crypto-m)#match address 170 R1(config-crypto-m)#exit R1(config)#crypto map mymap 18 ipsec-isakmp R1(config-crypto-m)#set peer 100.133.123.3 R1(config-crypto-m)#set transform-set 180cisco R1(config-crypto-m)#match address 180 R1(config)#crypto map mymap 19 ipsec-isakmp R1(config-crypto-m)#set peer 100.133.123.4 R1(config-crypto-m)#set transform-set 190cisco R1(config-crypto-m)#match address 190
R1(config)#interface ethernet 0 R1(config-if)#crypto map mymap
R2(config)#ip route 160.160.160.0 255.255.255.0 100.133.123.1
R2(config)#access-list 170 permit ip 170.170.170.0 0.0.0.255 160.160.160.0 0.0.0.255
R2(config)#crypto ipsec transform-set 170cisco esp-des esp-md5-hmac
R2(config)#crypto map mymap 17 ipsec-isakmp R2(config-crypto-m)#set peer 100.133.123.1 R2(config-crypto-m)#set transform-set 170cisco R2(config-crypto-m)#match address 170
R2(config)#interface ethernet 0 R2(config-if)#crypto map mymap
R3(config)#ip route 160.160.160.0 255.255.255.0 100.133.123.1
R3(config)#access-list 180 permit ip 180.180.180.0 0.0.0.255 160.160.160.0 0.0.0.255
R3(config)#crypto ipsec transform-set 180cisco esp-des esp-md5-hmac
R3(config)#crypto map mymap 18 ipsec-isakmp R3(config-crypto-m)#set peer 100.133.123.1 R3(config-crypto-m)#set transform-set 180cisco R3(config-crypto-m)#match address 180
R3(config)#interface ethernet 0 R3(config-if)#crypto map mymap
R3(config)#ip route 160.160.160.0 255.255.255.0 100.133.123.1
R3(config)#access-list 190 permit ip 190.190.190.0 0.0.0.255 160.160.160.0 0.0.0.255
R3(config)#crypto ipsec transform-set 190cisco esp-des esp-md5-hmac
R3(config)#crypto map mymap 19 ipsec-isakmp R3(config-crypto-m)#set peer 100.133.123.1 R3(config-crypto-m)#set transform-set 190cisco R3(config-crypto-m)#match address 190
R3(config)#interface ethernet 0 R3(config-if)#crypto map mymap
| [ LiB ] |