Cisco Ipsec Site-Site VPN

Cisco Ipsec Site-Site VPN Configuration :

Local Site :

crypto isakmp policy 1
 encr aes
 hash sha
 authentication pre-share
 group 2
crypto isakmp key test address 1.1.1.1
!
crypto ipsec transform-set comms esp-aes esp-sha-hmac
!
crypto map comms 1 ipsec-isakmp
 set peer 2.2.2.2
 set transform-set comms
 match address 102
!
access-list 102 permit ip 10.10.10.0 0.0.0.255 172.0.0.0 0.31.255.255
                              (Lan Ip)             (Remote Subnet)
!
!
access-list 101 deny ip 10.10.10.0 0.0.0.255 172.0.0.0 0.31.255.255
       (Deny Traffic to be NaTed over the VPN Link)
access-list 101 permit ip 10.10.10.0 0.0.0.255 any
       (Permit Local Traffic to be NaTed)
!
!
ip nat inside source list 101 interface Dialer0 overload
!
interface FA0/0
 description Connectioon_to_WAN
 ip address 1.1.1.1 255.255.255.0
 ip access-group INTERNET in
 ip nat outside
 crypto map comms
!
interface FA0/1
 description Connection_to_LAN
 ip address 10.10.10.1 255.255.255.0
 ip nat inside
!
ip access-list extended INTERNET
permit esp host 2.2.2.2 any
permit udp host 2.2.2.2 any eq isakmp
!
end

Remote Site :
crypto isakmp policy 1
 encr aes
 hash sha
 authentication pre-share
 group 2
crypto isakmp key test address 2.2.2.2
!
crypto ipsec transform-set comms esp-aes esp-sha-hmac
!
crypto map comms 1 ipsec-isakmp
 set peer 1.1.1.1
 set transform-set comms
 match address 102
!
access-list 102 permit ip 172.0.0.0 0.31.255.255 10.10.10.0 0.0.0.255
                               (Lan Ip)             (Remote Subnet)
!
!
access-list 101 deny ip 172.0.0.0 0.31.255.255 10.10.10.0 0.0.0.255
      (Deny Traffic to be NaTed over the VPN Link)
access-list 101 permit ip 172.0.0.0 0.31.255.255 any
      (Permit Local Traffic to be NaTed)
!
!
ip nat inside source list 101 interface Dialer0 overload
!
interface FA0/0
description Connectioon_to_WAN
ip address 2.2.2.2 255.255.255.0
ip access-group INTERNET in
ip nat outside
crypto map comms
!
interface FA0/1
description Connection_to_LAN
ip address 172.16.1.1 255.255.255.0
ip nat inside
!
ip access-list extended INTERNET
permit esp host 1.1.1.1 any
permit udp host 1.1.1.1 any eq isakmp
!
end

VPN Tweaks :

config terminal

crypto isakmp keepalive 15 10
!
crypto map comms securewan 1 ipsec-isakmp
set security-association lifetime kilobytes 18432000
set security-association lifetime seconds 86400
set security-association idle-time 7200

2 Types of VPN Encryption :

crypto ipsec transform-set esp-aes esp-md5-hmac
crypto ipsec transform-set esp-aes esp-sha-hmac
!
crypto isakmp policy 1
 hash md5
 hash sha