Cisco – IPSEC SITE-SITE EASY VPN + XAUTH + SPLIT TUNNELING
aaa authentication login easyvpnlist local
aaa authorization network Comms-Networks local
!
!
crypto isakmp policy 1
encr aes 256
authentication pre-share
group 2
crypto isakmp key test address 2.2.2.2 no-xauth
crypto isakmp client configuration address-pool local EASYVPN_POOL
crypto isakmp xauth timeout 60
!
crypto isakmp client configuration group Comms-Networks
key test
dns 192.168.3.1
domain Comms-Networks
pool EASYVPN_POOL
acl EASY_VPN_SUBNET_SPLIT_TUNNELING
save-password
pfs
max-users 5
netmask 255.255.255.248
!
crypto ipsec transform-set sitetosite+easyvpn esp-aes 256 esp-sha-hmac
!
crypto map site-to-site 30 ipsec-isakmp dynamic Comms-Networks
!
crypto map site-to-site client authentication list easyvpnlist
crypto map site-to-site client configuration address respond
crypto map site-to-site isakmp authorization list Comms-Networks
crypto map site-to-site 1 ipsec-isakmp dynamic Comms-Networks
!
crypto map site-to-site 1 ipsec-isakmp
set peer 2.2.2.2
set transform-set sitetosite+easyvpn
match address IPSEC_VPN_SUBNET
!
crypto dynamic-map Comms-Networks 10
set transform-set sitetosite+easyvpn
reverse-route
!
!
ip local pool EASYVPN_POOL 192.168.3.2 192.168.3.6
!
ip access-list extended IPSEC_VPN_SUBNET
remark ACCESS_LOCAL_SUBNET-TO-REMOTE_SUBNETS
permit ip 192.168.2.0 0.0.0.7 10.0.0.0 0.0.0.255
permit ip 192.168.2.0 0.0.0.7 10.0.1.0 0.0.0.255
!
ip access-list extended EASY_VPN_SUBNET_SPLIT_TUNNELING
permit ip 192.168.3.0 0.0.0.7 any
remark ACCESS_MEDIA_SERVERS
permit ip 192.168.2.0 0.0.0.7 any
!
interface vlan 2
description MEDIA_SERVER_INTERFACE
ip address 192.168.2.1 255.255.255.248
ip inspect myfw in
ip nat inside
!
interface loopback 3
description EASY_VPN_SERVER_INTERFACE
ip address 192.168.3.1 255.255.255.248
ip inspect myfw in
ip nat inside
!
ip nat inside source route-map SERVERS_RMAP interface FastEthernet0/0 overload
ip nat inside source route-map EASY_VPN_RMAP interface FastEthernet0/0 overload
!
route-map SERVERS_RMAP permit 1
match ip address 102
!
route-map EASY_VPN_RMAP permit 1
match ip address 103
!
remark IPSEC_TUNNEL_DENY_NAT
access-list 102 deny ip 192.168.2.0 0.0.0.7 10.0.0.0 0.0.0.255
access-list 102 deny ip 192.168.2.0 0.0.0.7 10.0.1.0 0.0.0.255
remark MEDIA_SERVER_DENY_NAT_TO_EASY_VPN_SERVER
access-list 102 deny ip 192.168.2.0 0.0.0.7 192.168.6.0 0.0.0.7
remark ALLOW_ANY
access-list 102 permit ip 192.168.2.0 0.0.0.7 any
!
remark EASY_VPN_SERVER_DENY_NAT_TO_MEADIA_SERVER
access-list 103 deny ip 192.168.3.0 0.0.0.7 192.168.2.0 0.0.0.7
remark ALLOW_ANY
access-list 103 permit ip 192.168.3.0 0.0.0.7 any
Bind crypto map to WAN Interface :
interface FastEthernet0/0
crypto map site-to-site