| [ LiB ] |
The following is a step-by-step discussion of the Practical Exercise solution.
IKE uses UDP port 500. The IPSec ESP and AH protocols use protocol numbers 50 and 51. You must ensure that any existing access lists you might already have configured do not block protocol 50, 51, and UDP port 500 traffic at any interface used by IPSec. In some cases you might need to reconfigure an existing access list to explicitly permit this traffic.
R1(config)#ip nat inside source route-map nonat interface Serial0 overload
R1(config)#access-list 150 deny ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255 R1(config)#access-list 150 deny ip 192.168.1.0 0.0.0.255 192.168.3.0 0.0.0.255 R1(config)#access-list 150 permit ip 192.168.1.0 0.0.0.255 any
R1(config)#route-map nonat permit 10 R1(config-route-map)#match ip address 150
R1(config)#interface serial0 R1(config-if)#ip nat outside R1(config-if)#exit R1(config)#interface ethernet0 R1(config-if)#ip nat inside
R2(config)#ip nat inside source route-map nonat interface Serial0 overload
R2(config)#access-list 150 deny ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255 R2(config)#access-list 150 deny ip 192.168.2.0 0.0.0.255 192.168.3.0 0.0.0.255 R2(config)#access-list 150 permit ip 192.168.2.0 0.0.0.255 any
R2(config)#route-map nonat permit 10 R2(config-route-map)#match ip address 150
R2(config)#interface serial0 R2(config-if)#ip nat outside R2(config-if)#exit R2(config)#interface ethernet0 R2(config-if)#ip nat inside
R3(config)#ip nat inside source route-map nonat interface Serial0 overload
R3(config)#access-list 150 deny ip 192.168.3.0 0.0.0.255 192.168.1.0 0.0.0.255 R3(config)#access-list 150 deny ip 192.168.3.0 0.0.0.255 192.168.2.0 0.0.0.255 R3(config)#access-list 150 permit ip 192.168.3.0 0.0.0.255 any
R3(config)#route-map nonat permit 10 R3(config-route-map)#match ip address 150
R3(config)#interface serial0 R3(config-if)#ip nat outside R3(config-if)#exit R3(config)#interface ethernet0 R3(config-if)#ip nat inside
R1(config)#crypto isakmp policy 4 R1(config-isakmp)#authentication pre-share
R1(config)#crypto isakmp key cisco1234 address 100.228.202.154 R1(config)#crypto isakmp key cisco1234 address 200.154.17.130
R2(config)#crypto isakmp policy 4 R2(config-isakmp)#authentication pre-share
R2(config)#crypto isakmp key cisco1234 address 100.228.202.154 R2(config)#crypto isakmp key cisco1234 address 100.232.202.210
R3(config)#crypto isakmp policy 4 R3(config-isakmp)#authentication pre-share
R3(config)#crypto isakmp key cisco1234 address 100.232.202.210 R3(config)#crypto isakmp key cisco1234 address 200.154.17.130
R1(config)#access-list 105 permit ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255 R1(config)#access-list 106 permit ip 192.168.1.0 0.0.0.255 192.168.3.0 0.0.0.255
R1(config)#crypto ipsec transform-set encrypt-des esp-des
R1(config)#crypto map combined local-address serial0 R1(config)#crypto map combined 20 ipsec-isakmp R1(config-crypto-m)#set peer 100.228.202.154 R1(config-crypto-m)#set transform-set encrypt-des R1(config-crypto-m)#match address 106 R1(config-crypto-m)#exit R1(config)#crypto map combined 30 ipsec-isakmp R1(config-crypto-m)#set peer 200.154.17.130 R1(config-crypto-m)#set transform-set encrypt-des R1(config-crypto-m)#match address 105
R1(config)#interface ethernet 0 R1(config-if)#crypto map combined
R2(config)#access-list 105 permit ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255 R2(config)#access-list 106 permit ip 192.168.2.0 0.0.0.255 192.168.3.0 0.0.0.255
R2(config)#crypto ipsec transform-set encrypt-des esp-des R2(config)#crypto ipsec transform-set 1600_box esp-des
R2(config)#crypto map combined local-address serial0 R2(config)#crypto map combined 7 ipsec-isakmp R2(config-crypto-m)#set peer 100.232.202.210 R2(config-crypto-m)#set transform-set 1600_box R2(config-crypto-m)#match address 105 R2(config-crypto-m)#exit R2(config)#crypto map combined 8 ipsec-isakmp R2(config-crypto-m)#set peer 100.228.202.154 R2(config-crypto-m)#set transform-set 1600_box R2(config-crypto-m)#match address 106
R2(config)#interface ethernet 0 R2(config-if)#crypto map combined
R3(config)#access-list 105 permit ip 192.168.3.0 0.0.0.255 192.168.1.0 0.0.0.255 R3(config)#access-list 106 permit ip 192.168.3.0 0.0.0.255 192.168.2.0 0.0.0.255
R3(config)#crypto ipsec transform-set encrypt-des esp-des R3(config)#crypto ipsec transform-set 1600_box esp-des
R3(config)#crypto map combined local-address serial0 R3(config)#crypto map combined 7 ipsec-isakmp R3(config-crypto-m)#set peer 100.232.202.210 R3(config-crypto-m)#set transform-set encrypt-des R3(config-crypto-m)#match address 106 R3(config)#crypto map combined 8 ipsec-isakmp R3(config-crypto-m)#set peer 200.154.17.130 R3(config-crypto-m)#set transform-set 1600_box R3(config-crypto-m)#match address 105
R3(config)#interface ethernet 0 R3(config-if)#crypto map combined
| [ LiB ] |