Cisco 887G – 3G IPSEC Hostname Identity VPN Configuration

3G ipsec VPN Configuration : Cellular 0
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec
service timestamps log datetime localtime show-timezone
service password-encryption
service internal
!

hostname comms30
!
boot-start-marker
boot-end-marker
!
logging message-counter syslog
logging buffered 8192 informational
no logging monitor
enable secret 5 $1$PnO9$1IcimGxIjiU4gM/cX.QYf.
!
aaa new-model
!
!
aaa authentication login default group tacacs+ local enable
aaa authorization exec default group tacacs+ local none
aaa authorization commands 0 default group tacacs+ local none
aaa authorization commands 1 default group tacacs+ local none
aaa authorization commands 15 default group tacacs+ local none
aaa accounting exec default
action-type start-stop
group tacacs+
!
aaa accounting commands 0 default
action-type start-stop
group tacacs+
!
aaa accounting commands 1 default
action-type start-stop
group tacacs+
!
aaa accounting commands 15 default
action-type start-stop
group tacacs+
!
!
!
aaa session-id common
memory-size iomem 10
clock summer-time GMT recurring last Sun Mar 1:00 last Sun Oct 1:00
!
!
ip source-route
!
!
ip dhcp excluded-address 10.10.38.1 10.10.38.29
ip dhcp excluded-address 10.10.38.101 10.10.38.254
!

ip dhcp pool DATA
import all
network 10.10.38.0 255.255.255.0
default-router 10.10.38.200
dns-server 10.10.38.200
lease 0 2
!
!
ip cef

ip domain name commsgroup.ww
ip inspect max-incomplete high 900
ip inspect max-incomplete low 800
ip inspect one-minute high 900
ip inspect one-minute low 800
ip inspect udp idle-time 15
ip inspect dns-timeout 10
ip inspect tcp idle-time 900
ip inspect name myfw cuseeme timeout 900
ip inspect name myfw ftp timeout 900
ip inspect name myfw rcmd timeout 900
ip inspect name myfw realaudio timeout 900
ip inspect name myfw smtp timeout 900
ip inspect name myfw tftp timeout 900
ip inspect name myfw udp timeout 15
ip inspect name myfw tcp timeout 900
ip inspect name myfw h323 timeout 900
ip inspect name myfw pptp timeout 900
no ipv6 cef
!
!
multilink bundle-name authenticated

chat-script vodafone “” “ATDT*98*1#” TIMEOUT 60 CONNECT
!
!
username root privilege 15 password 7 00031F09065A07110E3749
!
!
crypto isakmp policy 1
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp key commsr3m0t3 address 2.2.2.2

crypto isakmp identity hostname
crypto isakmp keepalive 15 10
!
!
crypto ipsec transform-set secure esp-3des esp-md5-hmac
!
crypto map mapping 1 ipsec-isakmp
set peer 2.2.2.2
set transform-set secure
match address VPN
!
archive
log config
hidekeys
!
!
ip tcp ecn
ip tcp selective-ack
ip tcp timestamp
ip tcp path-mtu-discovery
ip ssh version 1
bridge irb
!
!
!
interface ATM0
no ip address
shutdown
no atm ilmi-keepalive
dsl bitswap both
!
interface FastEthernet0
!

interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface Cellular0
ip address negotiated
ip nat outside
ip virtual-reassembly
encapsulation ppp
dialer in-band
dialer idle-timeout 0

dialer string vodafone
dialer-group 1
async mode interactive
ppp chap hostname web
ppp chap password 7 03135E09
ppp ipcp dns request
crypto map mapping
!
interface Vlan1
description Corporate VLAN
ip address 10.10.38.200 255.255.255.0
ip access-group LAN in
ip nat inside
ip inspect myfw in
ip virtual-reassembly
hold-queue 100 out
!
ip forward-protocol nd

ip route 0.0.0.0 0.0.0.0 Cellular0
no ip http server
no ip http secure-server
!
!
ip dns server
ip nat inside source route-map NAT interface Cellular0 overload
!
ip access-list standard TELNET_SSH
permit 2.2.2.9
permit 2.2.2.8 0.0.0.7
ip access-list standard COMMS_SNMP
permit 2.2.2.9
permit 2.2.2.8 0.0.0.7
!
ip access-list extended INTERNET
remark COMMS
permit ip 2.2.2.8 0.0.0.7 any
permit ip host 2.2.2.9 any
remark ISAKMP_VPN
permit esp host 2.2.2.2 any
permit udp host 2.2.2.2 any eq isakmp
remark ICMP
permit icmp any any administratively-prohibited
permit icmp any any echo-reply
permit icmp any any packet-too-big
permit icmp any any time-exceeded
permit icmp any any traceroute
permit icmp any any unreachable
remark DNS
permit udp host 80.74.16.30 any eq domain
permit udp host 80.74.16.31 any eq domain
remark NTP
permit udp host 80.74.16.30 any eq ntp
permit udp host 80.74.16.31 any eq ntp
remark DENY_ALL
deny   ip any any log
ip access-list extended LAN
permit udp any eq bootpc any eq bootps
permit ip 10.10.38.0 0.0.0.255 any
ip access-list extended NAT_ACL
deny   ip 10.10.38.0 0.0.0.255 10.10.0.0 0.0.255.255
permit ip 10.10.38.0 0.0.0.255 any
ip access-list extended VPN
permit ip 10.10.38.0 0.0.0.255 10.10.0.0 0.0.255.255
!
dialer-list 1 protocol ip permit
snmp-server community rocaww RO COMMS_SNMP
no cdp run
!

!
!
!
route-map NAT permit 10
match ip address name NAT_ACL
!
tacacs-server host 80.74.16.12
tacacs-server key  0 test
!
control-plane
!
bridge 1 protocol ieee
banner login #CCCCCC
!
** This is the property of Comms-Networks Limited. **

You are required to have personal authorisation from the Network Administrator
before you use this system. Unauthorised access of a computer constitutes an
offence under the Computer Misuse Act 1990.

If you understand this message and have been authorised to use this system
please enter your username and password below to continue this session.
Otherwise, you must disconnect from this session immediately.
All access to this device is logged.
!
#
!
line con 0
exec-timeout 15 0
no modem enable
stopbits 1
line aux 0
line 3
exec-timeout 0 0

script dialer vodafone
modem InOut
no exec
transport input all
rxspeed 7200000
txspeed 2000000
line 4
exec-timeout 0 0
timeout login response 0
privilege level 0
modem answer-timeout 0
modem dtr-delay 0
activation-character 0
exec-character-bits 8
special-character-bits 8
no exec
length 0
width 0
no history
no editing
transport preferred none
transport input none
transport output none
escape-character soft 0
escape-character 0
no ip tcp input-coalesce-threshold
callback forced-wait 0
callback nodsr-wait 0
stopbits 1
speed 115000
line vty 0 4
access-class TELNET_SSH in
exec-timeout 15 0
privilege level 15
transport input all
!
scheduler max-task-time 5000
sntp server 80.74.16.30
sntp server 80.74.16.31
end
!

3G ipsec VPN Configuration: Cellular 0 + Dialer 1

!
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec
service timestamps log datetime localtime show-timezone
service password-encryption
!

hostname comms30
!
boot-start-marker
boot-end-marker
!
logging message-counter syslog
logging buffered 8192 informational
no logging monitor
enable secret 5 $1$PnO9$1IcimGxIjiU4gM/cX.QYf.
!
aaa new-model
!
aaa authentication login default group tacacs+ local enable
aaa authorization exec default group tacacs+ local none
aaa authorization commands 0 default group tacacs+ local none
aaa authorization commands 1 default group tacacs+ local none
aaa authorization commands 15 default group tacacs+ local none
aaa accounting exec default
action-type start-stop
group tacacs+
!
aaa accounting commands 0 default
action-type start-stop
group tacacs+
!
aaa accounting commands 1 default
action-type start-stop
group tacacs+
!
aaa accounting commands 15 default
action-type start-stop
group tacacs+
!
!
!
aaa session-id common
memory-size iomem 10
clock summer-time GMT recurring last Sun Mar 1:00 last Sun Oct 1:00
!
!
ip source-route
!
!
ip dhcp excluded-address 10.10.38.1 10.10.38.29
ip dhcp excluded-address 10.10.38.101 10.10.38.254
!
ip dhcp pool DATA
import all
network 10.10.38.0 255.255.255.0
default-router 10.10.38.200
dns-server 10.10.38.200
lease 0 2
update arp
!
!
ip cef

ip domain name commsgroup.ww
ip inspect max-incomplete high 900
ip inspect max-incomplete low 800
ip inspect one-minute high 900
ip inspect one-minute low 800
ip inspect udp idle-time 15
ip inspect dns-timeout 10
ip inspect tcp idle-time 900
ip inspect name myfw cuseeme timeout 900
ip inspect name myfw ftp timeout 900
ip inspect name myfw rcmd timeout 900
ip inspect name myfw realaudio timeout 900
ip inspect name myfw smtp timeout 900
ip inspect name myfw tftp timeout 900
ip inspect name myfw udp timeout 15
ip inspect name myfw tcp timeout 900
ip inspect name myfw h323 timeout 900
ip inspect name myfw pptp timeout 900
no ipv6 cef
!
!
multilink bundle-name authenticated

chat-script vodafone “” “ATDT*98*1#” TIMEOUT 60 CONNECT
!
!
username root privilege 15 password 7 00031F09065A07110E3749
!
crypto isakmp policy 1
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp key commsr3m0t3 address 2.2.2.2

crypto isakmp identity hostname
crypto isakmp keepalive 15 10
!
!
crypto ipsec transform-set secure esp-3des esp-md5-hmac
!
crypto map mapping 1 ipsec-isakmp
set peer 2.2.2.2
set transform-set secure
match address VPN
!
archive
log config
hidekeys
!
!
ip tcp ecn
ip tcp selective-ack
ip tcp timestamp
ip tcp path-mtu-discovery
ip ssh version 1
bridge irb
!
!
!
interface ATM0
no ip address
shutdown
no atm ilmi-keepalive
!
interface FastEthernet0
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface Dialer1
ip address negotiated
ip virtual-reassembly
encapsulation ppp
dialer pool 1
dialer idle-timeout 0

dialer string vodafone
dialer persistent
dialer-group 1
no cdp enable
ppp chap hostname web
ppp chap password 7 0836494C
ppp ipcp dns request
crypto map mapping
!
interface Cellular0
no ip address
ip virtual-reassembly
encapsulation ppp
dialer in-band
dialer pool-member 1
load-interval 60
async mode interactive
!
interface Vlan1
description Corporate VLAN
ip address 10.10.38.200 255.255.255.0
ip nat inside
ip inspect myfw in
ip virtual-reassembly
hold-queue 100 out
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 Cellular0
no ip http server
no ip http secure-server
!
!
ip dns server
ip nat inside source route-map NAT interface Cellular0 overload
!
ip access-list standard TELNET_SSH
permit 2.2.2.9
permit 2.2.2.8 0.0.0.7
ip access-list standard COMMS_SNMP
permit 2.2.2.9
permit 2.2.2.8 0.0.0.7
!
ip access-list extended INTERNET
remark COMMS
permit ip 2.2.2.8 0.0.0.7 any
permit ip host 2.2.2.9 any
remark ISAKMP_VPN
permit esp host 2.2.2.2 any
permit udp host 2.2.2.2 any eq isakmp
remark ICMP
permit icmp any any administratively-prohibited
permit icmp any any echo-reply
permit icmp any any packet-too-big
permit icmp any any time-exceeded
permit icmp any any traceroute
permit icmp any any unreachable
remark DNS
permit udp host 80.74.16.30 any eq domain
permit udp host 80.74.16.31 any eq domain
remark NTP
permit udp host 80.74.16.30 any eq ntp
permit udp host 80.74.16.31 any eq ntp
remark DENY_ALL
deny   ip any any log
ip access-list extended NAT_ACL
deny   ip 10.10.38.0 0.0.0.255 10.10.0.0 0.0.255.255
permit ip 10.10.38.0 0.0.0.255 any
ip access-list extended VPN
permit ip 10.10.38.0 0.0.0.255 10.10.0.0 0.0.255.255
!
dialer-list 1 protocol ip permit
snmp-server community rocaww RO COMMS_SNMP
no cdp run
!
!
!
!
route-map NAT permit 10
match ip address name NAT_ACL
!
tacacs-server host 80.74.16.12
tacacs-server key 0 test
!
control-plane
!
bridge 1 protocol ieee
banner login ?CCCCCC
!
** This is the property of Comms-Networks Limited. **
You are required to have personal authorisation from the Network Administrator
before you use this system. Unauthorised access of a computer constitutes an
offence under the Computer Misuse Act 1990.
If you understand this message and have been authorised to use this system
please enter your username and password below to continue this session.
Otherwise, you must disconnect from this session immediately.
All access to this device is logged.
!?
!
line con 0
exec-timeout 15 0
no modem enable
stopbits 1
line aux 0
line 3
exec-timeout 0 0

script dialer vodafone
modem InOut
no exec
transport input all
rxspeed 7200000
txspeed 2000000
line 4
exec-timeout 0 0
timeout login response 0
privilege level 0
modem answer-timeout 0
modem dtr-delay 0
activation-character 0
exec-character-bits 8
special-character-bits 8
no exec
length 0
width 0
no history
no editing
transport preferred none
transport input none
transport output none
escape-character soft 0
escape-character 0
no ip tcp input-coalesce-threshold
callback forced-wait 0
callback nodsr-wait 0
stopbits 1
speed 115000
line vty 0 4
access-class TELNET_SSH in
exec-timeout 15 0
privilege level 15
transport input all
!
scheduler max-task-time 5000
sntp server 80.74.16.30
sntp server 80.74.16.31
end

If router is peering with a linux system on 2.2.2.2
See revised config:

On Linux peer address vpn config:

conn dodds30
left=2.2.2.2
leftsubnet=10.10.0.0/16
right=0.0.0.0
rightid=@comms30.commsgroup.ww
rightsubnet=10.10.38.0/24
authby=secret
keyexchange=ike
aggrmode=no
ikelifetime=24h
keylife=8h
keyingtries=3
rekey=no
auto=start
esp=3des-md5-96
pfs=no

Linux Shared Key config:

ipsec.secrets config :

%any 85.234.65.53 : PSK “commsr3m0t3″
@comms30.commsgroup.ww 2.2.2.2 : PSK “commsr3m0t3″