GRE Over IPsec & Configuartion
GRE Over IPsec & Configuartion
ISP(config)#int f 0/0
ISP(config-if)#ip add 1.0.0.2 255.255.255.252
ISP(config-if)#no
shutdown ISP(config-
if)#exit ISP(config)#int
f 1/0
ISP(config-if)#ip add 2.0.0.1 255.255.255.252
ISP(config-if)#no shutdown
ISP(config-if)#exit
Site-A(config)#int f 0/0
Site-A(config-if)#ip add 1.0.0.1 255.255.255.252
Site-A(config-if)#no shutdown
Site-A(config-
if)#exit Site-
Software / Network Engineer whatsapp : +923059299396
Sayed Hamza Jilllani
A(config)#int f 2/0
Site-A(config-if)#ip add 10.0.0.1 255.0.0.0
Site-A(config-if)#no shutdown
Site-A(config-if)#exit
Site-A(config)#ip route 2.0.0.0 255.255.255.252 1.0.0.2
Site-B(config)#int f 1/0
Site-B(config-if)#ip add 2.0.0.2 255.255.255.252
Site-B(config-if)#no shutdown
Site-B(config-if)#exit
Site-B(config)#int f
2/0
Site-B(config-if)#ip add 172.16.0.1 255.255.0.0
Site-B(config-if)#no shutdown
Site-B(config-if)#exit
Site-B(config)#ip route 1.0.0.0 0255.255.255.252 2.0.0.1
.
Site-B#ping 1.0.0.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 1.0.0.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 96/114/136
ms Site-B#
Site-A#ping 2.0.0.2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2.0.0.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 52/67/88
ms Site-A#
Site-A(config)#int tunnel 1
Site-A(config-if)#ip add 192.168.0.1 255.255.255.252
Site-A(config-if)#tunnel source fastEthernet 0/0
Site-A(config-if)#tunnel destination 2.0.0.2
Site-A(config-if)#exit
Site-B(config)#int tunnel 1
Site-B(config-if)#ip add 192.168.0.2 255.255.255.252
Site-B(config-if)#tunnel source fastEthernet 1/0
Site-B(config-if)#tunnel destination 1.0.0.1
Site-B(config-if)#exit
Site-B#ping 192.168.0.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.0.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 24/52/64
ms Site-B#
Site-A#ping 192.168.0.2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.0.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 24/56/88
ms Site-A#
Site-A(config)#router eigrp 1
Site-A(config-router)#network 10.0.0.0 255.0.0.0
Site-A(config-router)#network 192.168.0.0 255.255.255.252
Site-A(config-router)#exit
Site-B(config)#router eigrp 1
Site-B(config-router)#network 172.16.0.0 255.255.0.0
Site-B(config-router)#network 192.168.0.0 255.255.255.252
Site-B(config-router)#exit
IPSec Configuration
Site-A(config)#crypto isakmp policy 5
Site-A(config-isakmp)#encryption aes
Site-A(config-isakmp)#authentication pre-share
Site-A(config-isakmp)#group 2
Site-A(config-isakmp)#exit
Site-B(config-crypto-map)#exit
LAB
!Router ISP
Conf t
hostname ISP
int f 0/0
ip add 1.0.0.2 255.255.255.252
no shutdown
exit
int f 1/0
ip add 2.0.0.1 255.255.255.252
no shutdown
exit
!Site-A Router
conf t
hostname Site-
A int f 0/0
ip add 1.0.0.1 255.255.255.252
no shutdown
exit
int f 2/0
ip add 10.0.0.1 255.0.0.0
no shutdown
exit
Software / Network Engineer whatsapp : +923059299396
Sayed Hamza Jilllani
!Site-B Router
conf t
hostname Site-
B int f 1/0
ip add 2.0.0.2 255.255.255.252
no shutdown
exit
int f 2/0
ip add 172.16.0.1 255.255.0.0
no shutdown
exit
ip route 1.0.0.0 0255.255.255.252 2.0.0.1
!Site-A Router
int tunnel 1
ip add 192.168.0.1 255.255.255.252
tunnel source fastEthernet 0/0
tunnel destination 2.0.0.2
exit
!Site-B Router
int tunnel 1
ip add 192.168.0.2 255.255.255.252
tunnel source fastEthernet 1/0
tunnel destination 1.0.0.1
exit
!Site-A Router
router eigrp 1
network 10.0.0.0 255.0.0.0
network 192.168.0.0 255.255.255.252
exit
!site-B Router
router eigrp 1
network 172.16.0.0 255.255.0.0
network 192.168.0.0 255.255.255.252
exit
exit
crypto isakmp key corvit address 0.0.0.0 0.0.0.0
crypto ipsec transform-set TEST esp-aes esp-sha-
hmac mode transport
exit
ip access-list extended GRE
permit gre any any
exit
crypto map VPN 10 ipsec-
isakmp match address GRE
set transform-set
TEST set peer
2.0.0.2
exit
int fast 0/0
crypto map
VPN end