Configure and Verify A Site-to-Site IPsec VPN Using CLI
Configure and Verify A Site-to-Site IPsec VPN Using CLI
Addressing Table
© 2020 Cisco and/or its affiliates. All rights reserved. This document is Page 1 of
Cisco Public. 7
Packet Tracer - Configure and Verify a Site-to-Site IPsec VPN Using CLI
Background / Scenario
The network topology shows three routers. Your task is to configure R1 and R3 to support a
site-to-site IPsec VPN when traffic flows between their respective LANs. The IPsec VPN tunnel is
from R1 to R3 via R2. R2 acts as a pass-through and has no knowledge of the VPN. IPsec
provides secure transmission of sensitive information over unprotected networks, such as the
Internet. IPsec operates at the network layer and protects and authenticates IP packets
between participating IPsec devices (peers), such as Cisco routers.
ISAKMP Phase 1 Policy Parameters
Parameters R1 R3
Note: Bolded parameters are defaults. Only unbolded parameters have to be explicitly configured.
IPsec Phase 2 Policy Parameters
Parameters R1 R3
© 2020 Cisco and/or its affiliates. All rights reserved. This document is Page 2 of
Cisco Public. 7
Packet Tracer - Configure and Verify a Site-to-Site IPsec VPN Using CLI
© 2020 Cisco and/or its affiliates. All rights reserved. This document is Page 3 of
Cisco Public. 7
Packet Tracer - Configure and Verify a Site-to-Site IPsec VPN Using CLI
Bind the VPN-MAP crypto map to the outgoing Serial 0/0/0 interface.
© 2020 Cisco and/or its affiliates. All rights reserved. This document is Page 4 of
Cisco Public. 7
Packet Tracer - Configure and Verify a Site-to-Site IPsec VPN Using CLI
© 2020 Cisco and/or its affiliates. All rights reserved. This document is Page 5 of
Cisco Public. 7
Packet Tracer - Configure and Verify a Site-to-Site IPsec VPN Using CLI
Step 6: Perform a traceroute. What is the difference between PC-A and PC-C now compared to
at the beginning of the task?
© 2020 Cisco and/or its affiliates. All rights reserved. This document is Page 6 of
Cisco Public. 7
Packet Tracer - Configure and Verify a Site-to-Site IPsec VPN Using CLI
Extension Task
Extension Task – Add TWO additonal routers between R2 and R3. Use networks of your choice.
Configure OSPF on these networks. Add an additional PC off one of these networks. Observe a
traceroute to the new network. Observe a traceroute to the PC-C.
© 2020 Cisco and/or its affiliates. All rights reserved. This document is Page 7 of
Cisco Public. 7