Networking-Blog

My WordPress Blog

Cisco – IPSEC SITE-SITE EASY VPN + XAUTH + SPLIT TUNNELING

aaa authentication login easyvpnlist local
aaa authorization network Comms-Networks local
!
!
crypto isakmp policy 1
encr aes 256
authentication pre-share
group 2
crypto isakmp key test address 2.2.2.2 no-xauth
crypto isakmp client configuration address-pool local EASYVPN_POOL
crypto isakmp xauth timeout 60
!
crypto isakmp client configuration group Comms-Networks
key test
dns 192.168.3.1
domain Comms-Networks
pool EASYVPN_POOL
acl EASY_VPN_SUBNET_SPLIT_TUNNELING
save-password
pfs
max-users 5
netmask 255.255.255.248
!
crypto ipsec transform-set sitetosite+easyvpn esp-aes 256 esp-sha-hmac
!
crypto map site-to-site 30 ipsec-isakmp dynamic Comms-Networks
!
crypto map site-to-site client authentication list easyvpnlist
crypto map site-to-site client configuration address respond
crypto map site-to-site isakmp authorization list Comms-Networks
crypto map site-to-site 1 ipsec-isakmp dynamic Comms-Networks
!
crypto map site-to-site 1 ipsec-isakmp
set peer 2.2.2.2
set transform-set sitetosite+easyvpn
match address IPSEC_VPN_SUBNET
!
crypto dynamic-map Comms-Networks 10
set transform-set sitetosite+easyvpn
reverse-route
!
!
ip local pool EASYVPN_POOL 192.168.3.2 192.168.3.6
!
ip access-list extended IPSEC_VPN_SUBNET
remark ACCESS_LOCAL_SUBNET-TO-REMOTE_SUBNETS
permit ip 192.168.2.0 0.0.0.7 10.0.0.0 0.0.0.255
permit ip 192.168.2.0 0.0.0.7 10.0.1.0 0.0.0.255
!
ip access-list extended EASY_VPN_SUBNET_SPLIT_TUNNELING
permit ip 192.168.3.0 0.0.0.7 any
remark ACCESS_MEDIA_SERVERS
permit ip 192.168.2.0 0.0.0.7 any
!
interface vlan 2
description MEDIA_SERVER_INTERFACE
ip address 192.168.2.1 255.255.255.248
ip inspect myfw in
ip nat inside
!
interface loopback 3
description EASY_VPN_SERVER_INTERFACE
ip address 192.168.3.1 255.255.255.248
ip inspect myfw in
ip nat inside
!
ip nat inside source route-map SERVERS_RMAP interface FastEthernet0/0 overload
ip nat inside source route-map EASY_VPN_RMAP interface FastEthernet0/0 overload
!
route-map SERVERS_RMAP permit 1
match ip address 102
!
route-map EASY_VPN_RMAP permit 1
match ip address 103
!
remark IPSEC_TUNNEL_DENY_NAT
access-list 102 deny   ip 192.168.2.0 0.0.0.7 10.0.0.0 0.0.0.255
access-list 102 deny   ip 192.168.2.0 0.0.0.7 10.0.1.0 0.0.0.255
remark MEDIA_SERVER_DENY_NAT_TO_EASY_VPN_SERVER
access-list 102 deny   ip 192.168.2.0 0.0.0.7 192.168.6.0 0.0.0.7
remark ALLOW_ANY
access-list 102 permit ip 192.168.2.0 0.0.0.7 any
!
remark EASY_VPN_SERVER_DENY_NAT_TO_MEADIA_SERVER
access-list 103 deny ip 192.168.3.0 0.0.0.7 192.168.2.0 0.0.0.7
remark ALLOW_ANY
access-list 103 permit ip 192.168.3.0 0.0.0.7 any


Bind crypto map to WAN Interface
:

interface FastEthernet0/0
crypto map site-to-site

Cisco – EASY VPN SERVER with XAUTH and SPLIT TUNNELING

INTRODUCTION

How to configure a host to router Easy VPN Solution, based:
Cisco VPN Client, and Easy VPN Server
.

1. The Cisco Easy VPN negotiates tunnel parameters and establishes IPsec tunnels.
2. Xauth adds another level of authentication that identifies the user who
requests the IPsec connection.
3. Split tunneling enables the remote client to forward the Internet destined
traffic directly without forwarding it over the encrypted tunnel.

PREREQUISITES
The sample configuration is based on the following assumptions:

• The IP address at the Cisco Easy VPN Server is static.
• The IP address at the Cisco VPN Client is static or dynamic.
• The Cisco Easy VPN Client encrypts only traffic that is forwarded to the hub.
• Traffic destined for the Internet is forwarded, unencrypted, directly from the remote site.
• Traffic from the remote host is forwarded after applying Network Address Translation/Port
Address Translation (NAT/PAT).
• User level authentication is used for authorizing VPN access.

Configuration on Cisco Server end :

aaa authentication login easyvpnlist local
aaa authorization network Comms-Networks local
!
crypto isakmp policy 1
encr aes 256
authentication pre-share
group 2
crypto isakmp client configuration address-pool local EASYVPN_POOL
crypto isakmp xauth timeout 60
!
crypto isakmp client configuration group Comms-Networks
key P0wder07
dns 192.168.3.1
domain Comms-Networks
pool EASYVPN_POOL
acl EASY_VPN
save-password
pfs
max-users 5
netmask 255.255.255.248
!
crypto ipsec transform-set easyvpnvpn esp-aes 256 esp-sha-hmac
!
crypto dynamic-map Comms-Networks 10
set transform-set easyvpnvpn
reverse-route
!
crypto map easyvpn 3000 ipsec-isakmp dynamic Comms-Networks
!
crypto map easyvpn client authentication list easyvpnlist
crypto map easyvpn client configuration address respond
crypto map easyvpn isakmp authorization list Comms-Networks
crypto map easyvpn 1 ipsec-isakmp dynamic Comms-Networks
!
ip local pool EASYVPN_POOL 192.168.3.2 192.168.3.6
!
ip access-list extended EASY_VPN
permit ip 192.168.3.0 0.0.0.7 any
remark Access_to_Media_Server
permit ip 192.168.2.0 0.0.0.7 any
!
interface FastEthernet0/0
description WAN_INTERFACE
crypto map easyvpn

Note :

Don’t  forget to configure nonat DENY statement from the 192.168.2.0 network over to 192.168.3.0 network, same vice-versa. This will ensure no NAT traffic is going over the ipsec encrypted tunnel.

The nonat ACL will bind to the corresponing Interfaces where traffic is to be initiated from.