Networking-Blog

My WordPress Blog

Cisco – IPSEC SITE-SITE EASY VPN + XAUTH + SPLIT TUNNELING

aaa authentication login easyvpnlist local
aaa authorization network Comms-Networks local
!
!
crypto isakmp policy 1
encr aes 256
authentication pre-share
group 2
crypto isakmp key test address 2.2.2.2 no-xauth
crypto isakmp client configuration address-pool local EASYVPN_POOL
crypto isakmp xauth timeout 60
!
crypto isakmp client configuration group Comms-Networks
key test
dns 192.168.3.1
domain Comms-Networks
pool EASYVPN_POOL
acl EASY_VPN_SUBNET_SPLIT_TUNNELING
save-password
pfs
max-users 5
netmask 255.255.255.248
!
crypto ipsec transform-set sitetosite+easyvpn esp-aes 256 esp-sha-hmac
!
crypto map site-to-site 30 ipsec-isakmp dynamic Comms-Networks
!
crypto map site-to-site client authentication list easyvpnlist
crypto map site-to-site client configuration address respond
crypto map site-to-site isakmp authorization list Comms-Networks
crypto map site-to-site 1 ipsec-isakmp dynamic Comms-Networks
!
crypto map site-to-site 1 ipsec-isakmp
set peer 2.2.2.2
set transform-set sitetosite+easyvpn
match address IPSEC_VPN_SUBNET
!
crypto dynamic-map Comms-Networks 10
set transform-set sitetosite+easyvpn
reverse-route
!
!
ip local pool EASYVPN_POOL 192.168.3.2 192.168.3.6
!
ip access-list extended IPSEC_VPN_SUBNET
remark ACCESS_LOCAL_SUBNET-TO-REMOTE_SUBNETS
permit ip 192.168.2.0 0.0.0.7 10.0.0.0 0.0.0.255
permit ip 192.168.2.0 0.0.0.7 10.0.1.0 0.0.0.255
!
ip access-list extended EASY_VPN_SUBNET_SPLIT_TUNNELING
permit ip 192.168.3.0 0.0.0.7 any
remark ACCESS_MEDIA_SERVERS
permit ip 192.168.2.0 0.0.0.7 any
!
interface vlan 2
description MEDIA_SERVER_INTERFACE
ip address 192.168.2.1 255.255.255.248
ip inspect myfw in
ip nat inside
!
interface loopback 3
description EASY_VPN_SERVER_INTERFACE
ip address 192.168.3.1 255.255.255.248
ip inspect myfw in
ip nat inside
!
ip nat inside source route-map SERVERS_RMAP interface FastEthernet0/0 overload
ip nat inside source route-map EASY_VPN_RMAP interface FastEthernet0/0 overload
!
route-map SERVERS_RMAP permit 1
match ip address 102
!
route-map EASY_VPN_RMAP permit 1
match ip address 103
!
remark IPSEC_TUNNEL_DENY_NAT
access-list 102 deny   ip 192.168.2.0 0.0.0.7 10.0.0.0 0.0.0.255
access-list 102 deny   ip 192.168.2.0 0.0.0.7 10.0.1.0 0.0.0.255
remark MEDIA_SERVER_DENY_NAT_TO_EASY_VPN_SERVER
access-list 102 deny   ip 192.168.2.0 0.0.0.7 192.168.6.0 0.0.0.7
remark ALLOW_ANY
access-list 102 permit ip 192.168.2.0 0.0.0.7 any
!
remark EASY_VPN_SERVER_DENY_NAT_TO_MEADIA_SERVER
access-list 103 deny ip 192.168.3.0 0.0.0.7 192.168.2.0 0.0.0.7
remark ALLOW_ANY
access-list 103 permit ip 192.168.3.0 0.0.0.7 any


Bind crypto map to WAN Interface
:

interface FastEthernet0/0
crypto map site-to-site

Linux Ipsec VPN Dynamic IP

Fully qualified domain name in DNS of the right-hand side VPN device,
which is preceded by an @ sign. If DNS isn’t set up for the IP addresses,
remove this entry, because names that don’t resolve correctly cause the VPN initialization to fail
.

conn comms27
left=2.2.2.2
leftsubnet=10.10.0.0/16
right=0.0.0.0
rightid=@comms27.commsgroup.ww
rightsubnet=10.10.37.0/24
authby=secret
keyexchange=ike
aggrmode=no
ikelifetime=24h
keylife=8h
keyingtries=3
rekey=no
auto=start
esp=3des-md5-96
pfs=no
dpddelay=30
dpdtimeout=120
dpdaction=clear
type=transport

ipsec.secrets config :
%any 85.234.65.53 : PSK “commsr3m0t3”
@comms30.commsgroup.ww 85.234.65.53 : PSK “commsr3m0t3”

Table 35-1 Parameters of the /etc/ipsec.conf file

Parameter Description
Left Internet IP address of the left-hand side VPN device.
Leftsubnet The network protected by the left-hand side VPN device.
Leftid Fully qualified domain name in DNS of the left-hand side VPN device, which is preceded by an “@” sign. If DNS is set up for the IP addresses, remove this entry, because names that don’t resolve correctly cause the VPN initialization to fail.
Leftrsasigkey The entire left RSA sig public key for the left-hand side VPN device. This can be obtained by using the ipsec showhostkey --left command.
Leftnexthop The next hop router from the left-hand side VPN device when trying to reach the right-hand side VPN device. You may use an auto-generated variable %defaultroute, which will be valid in most cases, or the actual IP address of the next hop router in cases where the next hop is not the default router.
Right Internet IP address of the right-hand side VPN device.
Rightsubnet The network protected by the right-hand side VPN device.
Rightid Fully qualified domain name in DNS of the right-hand side VPN device, which is preceded by an @ sign. If DNS isn’t set up for the IP addresses, remove this entry, because names that don’t resolve correctly cause the VPN initialization to fail.
Rightrsasigkey The entire right RSA sig public key for the right-hand side VPN device. This can be obtained by using the ipsec showhostkey --right command.
Rightnexthop The next hop router from the right-hand side VPN device when trying to reach the right-hand side VPN device. You may use an auto-generated variable %defaultroute, which will be valid in most cases, or the actual IP address of the next hop router in cases where the next hop is not the default router.

Linux Cisco Ipsec Vpn Configuration

Linux Cisco Config :

86400  = 24hrs = Seconds
28800  = 8hrs    = Seconds

Linux Ipsec Directory Conf :

conn commstest1
left= “Remote Peer Address”
leftnexthop= “Gateway Address”
leftsubnet= “Remote Subnet Address”
right= ”Local Wan Address”
rightsubnet= “Local Subnet Address”
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
ikelifetime=8h
keylife=24h
keyingtries=3
pfs=no
rekey=yes
auto=start

Set Keepalives :

dpdaction=restart
dpddelay=15
dpdtimeout=60

dpddelay
Set the delay (in seconds) between Dead Peer Dectection (RFC 3706) keepalives (R_U_THERE, R_U_THERE_ACK) that are sent for this connection (default 30 seconds). If dpdtimeout is set, but not dpddelay, dpddelay will be set to the default.
dpdtimeout
Set the length of time (in seconds) we will idle without hearing either an R_U_THERE poll from our peer, or an R_U_THERE_ACK reply. After this period has elapsed with no response and no traffic, we will declare the peer dead, and remove the SA (default 120 seconds). If dpddelay is set, but not dpdtimeout, dpdtimeout will be set to the default.
dpdaction
When a DPD enabled peer is declared dead, what action should be taken. hold (default) means the eroute will be put into %hold status, while clear means the eroute and SA with both be cleared. dpdaction=clear is really only usefull on the server of a Road Warrior config.

Set Domain-Name:

Fully qualified domain name in DNS of the right-hand side VPN device, which is preceded by an @ sign.
If DNS isn’t set up for the IP addresses, remove this entry, because names that don’t resolve correctly cause
the VPN initialization to fail.

rightid=@commstest.co.uk

ipsec.secrets.conf

80.74.16.251 1.1.1.1 : PSK “commsvpn”
80.74.16.251 1.1.1.2 : PSK “commsvpn”
80.74.16.251 1.1.1.3 : PSK “commsvpn”
80.74.16.251 1.1.1.4 : PSK “commsvpn”
80.74.16.251 1.1.1.5 : PSK “commsvpn”

e.g : Template :

conn <<SITE_NAME>>
left=<<LOCAL_PHYSICAL_SERVER_PUBLC_IP_ADDRESS>>
leftnexthop=<<REMOTE_SITE_PUBLIC_ADDRESS>>
leftsubnet=<<LOCAL_PHYSICAL_SERVER_PUBLC_IP_ADDRESS>>
right=<<REMOTE_SITE_PUBLIC_ADDRESS>>
rightnexthop=<<LOCAL_PHYSICAL_SERVER_PUBLIC_IP_ADDRESS>>
rightsubnet=<<SITE_LAN_NETWORK_ADD>/<SUBNET_MASK>
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
ikelifetime=8h
keylife=24h
keyingtries=3
pfs=no
rekey=yes
auto=start
dpdaction=restart
dpddelay=15
dpdtimeout=60

Cisco Ipsec Site-Site VPN

Cisco Ipsec Site-Site VPN Configuration :

Local Site :

crypto isakmp policy 1
 encr aes
 hash sha
 authentication pre-share
 group 2
crypto isakmp key test address 1.1.1.1
!
crypto ipsec transform-set comms esp-aes esp-sha-hmac
!
crypto map comms 1 ipsec-isakmp
 set peer 2.2.2.2
 set transform-set comms
 match address 102
!
access-list 102 permit ip 10.10.10.0 0.0.0.255 172.0.0.0 0.31.255.255
                              (Lan Ip)             (Remote Subnet)
!
!
access-list 101 deny ip 10.10.10.0 0.0.0.255 172.0.0.0 0.31.255.255
       (Deny Traffic to be NaTed over the VPN Link)
access-list 101 permit ip 10.10.10.0 0.0.0.255 any
       (Permit Local Traffic to be NaTed)
!
!
ip nat inside source list 101 interface Dialer0 overload
!
interface FA0/0
 description Connectioon_to_WAN
 ip address 1.1.1.1 255.255.255.0
 ip access-group INTERNET in
 ip nat outside
 crypto map comms
!
interface FA0/1
 description Connection_to_LAN
 ip address 10.10.10.1 255.255.255.0
 ip nat inside
!
ip access-list extended INTERNET
permit esp host 2.2.2.2 any
permit udp host 2.2.2.2 any eq isakmp
!
end

Remote Site :
crypto isakmp policy 1
 encr aes
 hash sha
 authentication pre-share
 group 2
crypto isakmp key test address 2.2.2.2
!
crypto ipsec transform-set comms esp-aes esp-sha-hmac
!
crypto map comms 1 ipsec-isakmp
 set peer 1.1.1.1
 set transform-set comms
 match address 102
!
access-list 102 permit ip 172.0.0.0 0.31.255.255 10.10.10.0 0.0.0.255
                               (Lan Ip)             (Remote Subnet)
!
!
access-list 101 deny ip 172.0.0.0 0.31.255.255 10.10.10.0 0.0.0.255
      (Deny Traffic to be NaTed over the VPN Link)
access-list 101 permit ip 172.0.0.0 0.31.255.255 any
      (Permit Local Traffic to be NaTed)
!
!
ip nat inside source list 101 interface Dialer0 overload
!
interface FA0/0
description Connectioon_to_WAN
ip address 2.2.2.2 255.255.255.0
ip access-group INTERNET in
ip nat outside
crypto map comms
!
interface FA0/1
description Connection_to_LAN
ip address 172.16.1.1 255.255.255.0
ip nat inside
!
ip access-list extended INTERNET
permit esp host 1.1.1.1 any
permit udp host 1.1.1.1 any eq isakmp
!
end

VPN Tweaks :

config terminal

crypto isakmp keepalive 15 10
!
crypto map comms securewan 1 ipsec-isakmp
set security-association lifetime kilobytes 18432000
set security-association lifetime seconds 86400
set security-association idle-time 7200

2 Types of VPN Encryption :

crypto ipsec transform-set esp-aes esp-md5-hmac
crypto ipsec transform-set esp-aes esp-sha-hmac
!
crypto isakmp policy 1
 hash md5
 hash sha

Cisco GRE Tunnel Over Ipsec VPN

Cisco GRE Tunnel over IPSEC VPN Configuration:

 Router 1 Configuration:crypto isakmp policy 10
encryption aes 128
hash sha
autentication pre-share
group 2
!
crypto isakmp key cisco address 193.1.1.1 255.255.255.255 no-xauth
crypto ipsec transform-set ciscotransit esp-aes esp-sha-hmac
!
crypto ipsec profile VTI
set transform-set ciscotransit
exit
!
interface tunnel 0
ip address 10.10.12.1 255.255.255.0
tunnel source 192.1.1.1
tunnel destination 193.1.1.1
tunnel mode ipsec ipv4
tunnel protection ipsec VTI
!
interface G0/1
ip address 192.1.1.1 255.255.255.0
exit
!
interface G0/0
ip address 10.10.10.1 255.255.255.0
exit
!
ip route 10.10.11.0 255.255.255.0 tunnel 0
end
!

Router 2 Configuration on Remote end:

crypto isakmp policy 10
encryption aes 128
hash sha
autentication pre-share
group 2
!
crypto isakmp key cisco address 192.1.1.1 255.255.255.255 no-xauth
crypto ipsec transform-set ciscotransit esp-aes esp-sha-hmac
!
crypto ipsec profile VTI
set transform-set ciscotransit
!
interface tunnel 0
ip address 10.10.12.3 255.255.255.0
tunnel source 193.1.1.1
tunnel destination 192.1.1.1
tunnel mode ipsec ipv4
tunnel protection ipsec VTI
!
interface G0/1
ip address 193.1.1.1 255.255.255.0
!
interface G0/0
ip address 10.10.11.1 255.255.255.0
!
ip route 10.10.10.0 255.255.255.0 tunnel 0

Notes:

tunnel mode ipsec ipv4

 “Command to notify the router that this is an IPSec-based interface rather than GRE”.

 tunnel protection ipsec

 “Command to choose the type of encryption (transform-set) for the interface”.

Note:

What I did was create the tunnel interfaces on both ends

Enable EIGRP and enable the process on the tunnel ip addresses

Then I created a loopback interface and advertised that into EIGRP

Now I can track the route so if the main interface would drop the tunnel would still show up/up  but would drop its EIGRP adjacency which would drop the route.

Show Commands:

show ip interface brief
show crypto isakmp sa
sh0w crypto ipsec sa
show crypto session