0% found this document useful (0 votes)
5 views10 pages

Security: Labs Networking in Packet Tracer

Uploaded by

mahasin.hassan96
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views10 pages

Security: Labs Networking in Packet Tracer

Uploaded by

mahasin.hassan96
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 10

Labs Networking in Packet Tracer

Security

Mad by
Ahmed Abou_ELmaged Shallan Allam

Labs Cisco

Eng: - Ahmed Allam


Lab 1

Interface Site 1 Site 2 Network


Gig0/0 20.0.0.1 10.0.0.2 10.0.0.0/8
Gi0/1 10.0.0.1 30.0.0.1 20.0.0.0/8
30.0.0.0/8

Site Site 1 Site 2


IP Network 20.0.0.10 30.0.0.10
Gateway 20.0.0.1 30.0.0.1

Eng: - Ahmed Allam


Configurations

Site 1
Site1(config)#
Site1(config)#int g0/0
Site1(config-if)#ip add 10.0.0.1 255.0.0.0
Site1(config-if)#no sh
Site1(config-if)#int g0/1
Site1(config-if)#ip add 20.0.0.1 255.0.0.0
Site1(config-if)#no sh
Site1(config-if)#exit
Site1(config)#ip route 30.0.0.0 255.0.0.0 10.0.0.2
Site1(config)#

Site1(config)#crypto isakmp policy 10


Site1(config-isakmp)#encryption aes
Site1(config-isakmp)#hash sha
Site1(config-isakmp)#authentication pre-share
Site1(config-isakmp)#group 2
Site1(config-isakmp)#lifetime 86400
Site1(config-isakmp)#exit
Site1(config)#

Site1(config)#crypto isakmp key vpnpa55 address 10.0.0.2


Site1(config)#crypto ipsec transform-set MY_TRANSFORM_SET esp-aes esp-sha-hmac

Site1(config)#access-list 101 permit ip 20.0.0.0 0.255.255.255 30.0.0.0 0.255.255.255


Site1(config)#crypto map MY_CRYPTO_MAP 10 ipsec-isakmp
Site1(config-crypto-map)#set peer 10.0.0.2
Site1(config-crypto-map)#match address 101
Site1(config-crypto-map)#set transform-set MY_TRANSFORM_SET
Site1(config-crypto-map)#interface g0/1
Site1(config-if)#crypto map MY_CRYPTO_MAP
Site1(config-if)#

Eng: - Ahmed Allam


Site 2
Site2(config)#
Site2(config)#int g0/0
Site2(config-if)#ip add 10.0.0.2 255.0.0.0
Site2(config-if)#no sh
Site2(config-if)#int g0/1
Site2(config-if)#ip add 30.0.0.1 255.0.0.0
Site2(config-if)#no sh
Site2(config-if)#exit
Site2(config)#ip route 20.0.0.0 255.0.0.0 10.0.0.1
Site2(config)#

Site2(config)#crypto isakmp policy 10


Site2(config-isakmp)#encryption aes
Site2(config-isakmp)#hash sha
Site2(config-isakmp)#authentication pre-share
Site2(config-isakmp)#group 2
Site2(config-isakmp)#lifetime 86400
Site2(config-isakmp)#exit
Site2(config)#

Site2(config)#crypto isakmp key vpnpa55 address 10.0.0.1


Site2(config)#crypto ipsec transform-set MY_TRANSFORM_SET esp-aes esp-sha-hmac

Site2(config)#access-list 101 permit ip 30.0.0.0 0.255.255.255 20.0.0.0 0.255.255.255


Site2(config)#crypto map MY_CRYPTO_MAP 10 ipsec-isakmp
Site2(config-crypto-map)#set peer 10.0.0.1
Site2(config-crypto-map)#match address 101
Site2(config-crypto-map)#set transform-set MY_TRANSFORM_SET
Site2(config-crypto-map)#interface g0/0
Site2(config-if)#crypto map MY_CRYPTO_MAP
Site2(config-if)#

Eng: - Ahmed Allam


Ping Site1 to Site2

Ping Site2 to Site1

Test VPN in two Routers

Eng: - Ahmed Allam


Lab 2

Interface Site 1 Site 2 Internet


Gig0/0 10.0.0.1 30.0.0.2 20.0.0.2
Gig0/1 20.0.0.1 40.0.0.1 30.0.0.1

Network
PCs PCSite_1 PCSite_2
10.0.0.0/8
20.0.0.0/8 IP Network 10.0.0.10 40.0.0.10
30.0.0.0/8 Gateway 10.0.0.1 40.0.0.1
40.0.0.0/8

Eng: - Ahmed Allam


Configurations

Site 1
Site1(config)#
Site1(config)#int g0/0
Site1(config-if)#ip add 10.0.0.1 255.0.0.0
Site1(config-if)#no sh
Site1(config-if)#int g0/1
Site1(config-if)#ip add 20.0.0.1 255.0.0.0
Site1(config-if)#no sh
Site1(config-if)#exit
Site1(config)#router rip
Site1(config-router)#version 2
Site1(config-router)#network 10.0.0.0
Site1(config-router)#network 20.0.0.0
Site1(config-router)#exit
Site1(config)#
Site1(config)#crypto isakmp policy 10
Site1(config-isakmp)#encryption aes
Site1(config-isakmp)#hash sha
Site1(config-isakmp)#authentication pre-share
Site1(config-isakmp)#group 2
Site1(config-isakmp)#lifetime 86400
Site1(config-isakmp)#exit
Site1(config)#

Site1(config)#crypto isakmp key vpnpa55 address 30.0.0.2


Site1(config)#crypto ipsec transform-set MY_TRANSFORM_SET esp-aes esp-sha-hmac
Site1(config)#access-list 101 permit ip 10.0.0.0 0.255.255.255 40.0.0.0 0.255.255.255
Site1(config)#crypto map MY_CRYPTO_MAP 10 ipsec-isakmp
Site1(config-crypto-map)#set peer 30.0.0.2
Site1(config-crypto-map)#match address 101
Site1(config-crypto-map)#set transform-set MY_TRANSFORM_SET
Site1(config-crypto-map)#interface g0/1
Site1(config-if)#crypto map MY_CRYPTO_MAP
Site1(config-if)#

Eng: - Ahmed Allam


Site 2
Site2(config)#
Site2(config)#int g0/0
Site2(config-if)#ip add 30.0.0.2 255.0.0.0
Site2(config-if)#no sh
Site2(config-if)#int g0/1
Site2(config-if)#ip add 40.0.0.1 255.0.0.0
Site2(config-if)#no sh
Site2(config-if)#exit
Site2(config)#router rip
Site2(config-router)#version 2
Site2(config-router)#network 30.0.0.0
Site2(config-router)#network 40.0.0.0
Site2(config-router)#exit
Site2(config)#
Site2(config)#crypto isakmp policy 10
Site2(config-isakmp)#encryption aes
Site2(config-isakmp)#hash sha
Site2(config-isakmp)#authentication pre-share
Site2(config-isakmp)#group 2
Site2(config-isakmp)#lifetime 86400
Site2(config-isakmp)#exit
Site2(config)#

Site2(config)#crypto isakmp key vpnpa55 address 20.0.0.1


Site2(config)#crypto ipsec transform-set MY_TRANSFORM_SET esp-aes esp-sha-hmac
Site2(config)#access-list 101 permit ip 40.0.0.0 0.255.255.255 10.0.0.0 0.255.255.255
Site2(config)#crypto map MY_CRYPTO_MAP 10 ipsec-isakmp
Site2(config-crypto-map)#set peer 20.0.0.1
Site2(config-crypto-map)#match address 101
Site2(config-crypto-map)#set transform-set MY_TRANSFORM_SET
Site2(config-crypto-map)#interface g0/0
Site2(config-if)#crypto map MY_CRYPTO_MAP
Site2(config-if)#

Eng: - Ahmed Allam


Internet
Internet(config)#
Internet(config)#int g0/0
Internet(config-if)#ip add 20.0.0.2 255.0.0.0
Internet(config-if)#no sh
Internet(config-if)#int g0/1
Internet(config-if)#ip add 30.0.0.1 255.0.0.0
Internet(config-if)#no sh
Internet(config-if)#exit
Internet(config)#router rip
Internet(config-router)#version 2
Internet(config-router)#network 20.0.0.0
Internet(config-router)#network 30.0.0.0
Internet(config-router)#exit
Internet(config)#

Ping Site1 to Site2

Eng: - Ahmed Allam


Ping Site2 to Site1

Testing VPN

Thanks

Eng: - Ahmed Allam

You might also like