Cisco Linux ipsec VPN Hostname Identity Configuration

Defines the identity the router uses when participating in the IKE protocol.

hostname comms30
!

ip domain name commsgroup.ww
!

crypto isakmp policy 1
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp key commsr3m0t3 address 2.2.2.2

crypto isakmp identity hostname
crypto isakmp keepalive 15 10
!
crypto ipsec transform-set secure esp-3des esp-md5-hmac
!

crypto map mapping 1 ipsec-isakmp
set peer 2.2.2.2
set transform-set secure
match address VPN
!
ip nat inside source route-map NAT interface dialer0 overload
!
ip access-list extended NAT_ACL
deny ip 10.10.38.0 0.0.0.255 10.10.0.0 0.0.255.255
permit ip 10.10.38.0 0.0.0.255 any
!
ip access-list extended VPN
permit ip 10.10.38.0 0.0.0.255 10.10.0.0 0.0.255.255
!
route-map NAT permit 10
match ip address name NAT_ACL

Defines the identity the router uses when participating in the IKE protocol.
In order to use crypto isakmp identity hostname command : Configure the following :

hostname comms30
ip domain name commsgroup.ww
crypto isakmp identity hostname

On Linux peer address vpn config:

conn comms30
left=2.2.2.2
leftsubnet=10.10.0.0/16
right=0.0.0.0
rightid=@comms30.commsgroup.ww
rightsubnet=10.10.38.0/24
authby=secret
keyexchange=ike
aggrmode=no
ikelifetime=24h
keylife=8h
keyingtries=3
rekey=no
auto=start
esp=3des-md5-96
pfs=no

Linux Shared Key config:

ipsec.secrets config :

%any 2.2.2.2 : PSK “commsr3m0t3″
or
2.2.2.2 %any : PSK “commsr3m0t3″

If the remote user is behind a NAT-T Router / Firewall  and further connected
via a point-to-point link and remote user has a default-gateway of a private
LAN address
:

Scenerio :

So you have an internet facing Layer3 Router connected to another Layer3 Router,
behind this we have our remote user vpn router “cisco 857“.

NAT Traversal performs two tasks: it detects if both ends support NAT-T and
NAT-Discovery that detects NAT devices along the transmission path.
NAT-T encapsulate IPSec packets in UDP packets with port 4500
NAT-traversal encapsulates the ESP packets in UDP packets.

Internet Key Exchange (IKE) – User Datagram Protocol (UDP) port 500
Encapsulating Security Payload (ESP) – IP protocol number 50
IPsec NAT-T – UDP port 4500

eg :

Host Lan :
192.168.4.0/24

Default-Gateway :
192.168.2.127/30

Router/Firewall :
81.174.141.198

Remote Host Router is configured with :

Hostname
Domain-Name
Crypto Isakmp Hostname Identity

We know the remote NAT-T Firewall Router also there private lan default-gateway.
Here is the Linux ipsec configuration :

conn comms30
left=2.2.2.2
leftsubnet=10.10.0.0/16
right=0.0.0.0
rightid=@comms30.commsgroup.ww
rightnexthop=192.168.2.127
rightsubnet=192.168.4.0/24
rightsourceip=81.174.141.198
authby=secret
keyexchange=ike
aggrmode=no
ikelifetime=24h
keylife=8h
keyingtries=3
rekey=no
auto=start
esp=3des-md5-96
pfs=no
dpddelay=30
dpdtimeout=120
dpdaction=clear