Networking-Blog

My WordPress Blog

Cisco Ipsec Identity Hostname

The ISAKMP identity is the interface from which the remote router will
send ISAKMP messages to the local peer. If a router supports ISAKMP on
multiple interfaces, then hostnames should be used for ISAKMP identity
.

To configure a router to send its hostname in its ISAKMP peer negotiations,
use the global command

<crypto isakmp identity {hostname | address}>.

The default is to use the router’s ISAKMP interface IP address.

If the hostname option is used to identify its ISAKMP negotiations,
the remote peer hosts need to have hostname-to-IP-address mapping
,

achieved with <ip host {hostname} {IP address1} {IP Address 2…IP Address 8}>.

A router can also use DNS for hostname resolution, but local hostname
definitions are faster and don’t break if there is a DNS server problem.


Below is a pre-shared key configuration example between two routers. The local router
sends it hostname, and the remote machine sends its IP address.

First is the configuration on the local peer router (both the IP address and hostname
keys have been defined
):

The configuration on the local router looks like this :

!
hostname outlan-rt01
!
!
crypto isakmp policy 10
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp key secretkey address 192.168.10.3
crypto isakmp identity hostname
!
interface FastEthernet0/0
ip address 172.30.80.17 255.255.255.252
!

The configuration on the remote peer router looks like this:

!
hostname inlan-rt01
!
ip host outlan-rt01 172.30.80.17
!
!
crypto isakmp policy 10
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp key secretkey address outlan-rt01
!
interface FastEthernet1/0
ip address 192.168.10.3 255.255.255.252

Cisco Linux ipsec VPN Hostname Identity Configuration

Defines the identity the router uses when participating in the IKE protocol.

hostname comms30
!

ip domain name commsgroup.ww
!

crypto isakmp policy 1
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp key commsr3m0t3 address 2.2.2.2

crypto isakmp identity hostname
crypto isakmp keepalive 15 10
!
crypto ipsec transform-set secure esp-3des esp-md5-hmac
!

crypto map mapping 1 ipsec-isakmp
set peer 2.2.2.2
set transform-set secure
match address VPN
!
ip nat inside source route-map NAT interface dialer0 overload
!
ip access-list extended NAT_ACL
deny ip 10.10.38.0 0.0.0.255 10.10.0.0 0.0.255.255
permit ip 10.10.38.0 0.0.0.255 any
!
ip access-list extended VPN
permit ip 10.10.38.0 0.0.0.255 10.10.0.0 0.0.255.255
!
route-map NAT permit 10
match ip address name NAT_ACL

Defines the identity the router uses when participating in the IKE protocol.
In order to use crypto isakmp identity hostname command : Configure the following :

hostname comms30
ip domain name commsgroup.ww
crypto isakmp identity hostname

On Linux peer address vpn config:

conn comms30
left=2.2.2.2
leftsubnet=10.10.0.0/16
right=0.0.0.0
rightid=@comms30.commsgroup.ww
rightsubnet=10.10.38.0/24
authby=secret
keyexchange=ike
aggrmode=no
ikelifetime=24h
keylife=8h
keyingtries=3
rekey=no
auto=start
esp=3des-md5-96
pfs=no

Linux Shared Key config:

ipsec.secrets config :

%any 2.2.2.2 : PSK “commsr3m0t3″
or
2.2.2.2 %any : PSK “commsr3m0t3″

If the remote user is behind a NAT-T Router / Firewall  and further connected
via a point-to-point link and remote user has a default-gateway of a private
LAN address
:

Scenerio :

So you have an internet facing Layer3 Router connected to another Layer3 Router,
behind this we have our remote user vpn router “cisco 857“.

NAT Traversal performs two tasks: it detects if both ends support NAT-T and
NAT-Discovery that detects NAT devices along the transmission path.
NAT-T encapsulate IPSec packets in UDP packets with port 4500
NAT-traversal encapsulates the ESP packets in UDP packets.

Internet Key Exchange (IKE) – User Datagram Protocol (UDP) port 500
Encapsulating Security Payload (ESP) – IP protocol number 50
IPsec NAT-T – UDP port 4500

eg :

Host Lan :
192.168.4.0/24

Default-Gateway :
192.168.2.127/30

Router/Firewall :
81.174.141.198

Remote Host Router is configured with :

Hostname
Domain-Name
Crypto Isakmp Hostname Identity

We know the remote NAT-T Firewall Router also there private lan default-gateway.
Here is the Linux ipsec configuration :

conn comms30
left=2.2.2.2
leftsubnet=10.10.0.0/16
right=0.0.0.0
rightid=@comms30.commsgroup.ww
rightnexthop=192.168.2.127
rightsubnet=192.168.4.0/24
rightsourceip=81.174.141.198
authby=secret
keyexchange=ike
aggrmode=no
ikelifetime=24h
keylife=8h
keyingtries=3
rekey=no
auto=start
esp=3des-md5-96
pfs=no
dpddelay=30
dpdtimeout=120
dpdaction=clear