Cisco GRE Tunnel Over Ipsec VPN
Cisco GRE Tunnel over IPSEC VPN Configuration:
Router 1 Configuration:crypto isakmp policy 10
encryption aes 128
hash sha
autentication pre-share
group 2
!
crypto isakmp key cisco address 193.1.1.1 255.255.255.255 no-xauth
crypto ipsec transform-set ciscotransit esp-aes esp-sha-hmac
!
crypto ipsec profile VTI
set transform-set ciscotransit
exit
!
interface tunnel 0
ip address 10.10.12.1 255.255.255.0
tunnel source 192.1.1.1
tunnel destination 193.1.1.1
tunnel mode ipsec ipv4
tunnel protection ipsec VTI
!
interface G0/1
ip address 192.1.1.1 255.255.255.0
exit
!
interface G0/0
ip address 10.10.10.1 255.255.255.0
exit
!
ip route 10.10.11.0 255.255.255.0 tunnel 0
end
!
Router 2 Configuration on Remote end:
crypto isakmp policy 10
encryption aes 128
hash sha
autentication pre-share
group 2
!
crypto isakmp key cisco address 192.1.1.1 255.255.255.255 no-xauth
crypto ipsec transform-set ciscotransit esp-aes esp-sha-hmac
!
crypto ipsec profile VTI
set transform-set ciscotransit
!
interface tunnel 0
ip address 10.10.12.3 255.255.255.0
tunnel source 193.1.1.1
tunnel destination 192.1.1.1
tunnel mode ipsec ipv4
tunnel protection ipsec VTI
!
interface G0/1
ip address 193.1.1.1 255.255.255.0
!
interface G0/0
ip address 10.10.11.1 255.255.255.0
!
ip route 10.10.10.0 255.255.255.0 tunnel 0
Notes:
tunnel mode ipsec ipv4
“Command to notify the router that this is an IPSec-based interface rather than GRE”.
tunnel protection ipsec
“Command to choose the type of encryption (transform-set) for the interface”.
Note:
What I did was create the tunnel interfaces on both ends
Enable EIGRP and enable the process on the tunnel ip addresses
Then I created a loopback interface and advertised that into EIGRP
Now I can track the route so if the main interface would drop the tunnel would still show up/up but would drop its EIGRP adjacency which would drop the route.
Show Commands:
show ip interface brief
show crypto isakmp sa
sh0w crypto ipsec sa
show crypto session