Cisco 887G ADSL + 3G Backup
VPN IP SLA – In order to keep vpn up and active.
IP SLA MONITOR STATIC FLOATING ROUTE SOURCE LAN :
ip sla 1
icmp-echo 10.20.0.1 source-interface vlan 1
threshold 2
timeout 1000
frequency 5
!
!
ip sla schedule 1 life forever start-time now
!
!
ip sla 10
icmp-echo 80.74.16.173 source-interface Dialer0
threshold 2
timeout 1000
frequency 5
!
ip sla schedule 10 life forever start-time now
ip sla responder
!
track 10 interface ATM0 line-protocol
delay down 15 up 15
!
!
ip route 0.0.0.0 0.0.0.0 Dialer0 name PRIMARY track 10
ip route 0.0.0.0 0.0.0.0 Cellular0 name 3G_BACKUP
!
Rest of the Configuration :
ADSL :
service internal
!
interface ATM0
no ip address
atm vc-per-vp 64
atm bandwidth dynamic
atm ilmi-keepalive 30 retry 5
pvc 0/38
encapsulation aal5mux ppp dialer
dialer pool-member 1
!
dsl sync interval 3
dsl sync mode itu
dsl operating-mode itu-dmt
dsl power-cutback 1
dsl noise-margin 3
dsl max-tone-bits 10
dsl bitswap both
!
interface Dialer0
ip address negotiated
ip verify unicast reverse-path
ip access-group INTERNET in
ip nat outside
encapsulation ppp
dialer pool 1
dialer-group 1
ppp authentication chap callin
ppp chap hostname test@securewan.co.uk
ppp chap password 0 password
ppp ipcp dns request
crypto map mapping
!
3G Interface
chat-script mobile “” “ATDT*98*1#” TIMEOUT 60 CONNECT
interface Cellular0
ip address negotiated
ip nat outside
encapsulation ppp
dialer in-band
dialer idle-timeout 0
dialer string mobile
dialer-group 1
ppp chap hostname web
ppp chap password 7 10590C1B
ppp ipcp dns request
crypto map mapping
!
!
interface Vlan1
description Corporate VLAN
ip address 10.20.4.100 255.255.255.0
ip access-group LAN in
ip tcp adjust-mss 1400
!
DNS Name-Server :
ip name-server 80.74.16.30
ip name-server 80.74.16.31
ip name-server 8.8.8.8
ip dns server
!
ip nat inside source route-map NAT_WW interface Dialer0 overload
ip nat inside source route-map NAT_3G interface Cellular0 overload
!
ip access-list extended NAT_ACL_WW
deny ip 10.20.4.0 0.0.0.255 10.20.0.0 0.0.255.255
permit ip 10.20.4.0 0.0.0.255 any
deny ip any any
!
ip access-list extended NAT_ACL_3G
deny ip 10.20.4.0 0.0.0.255 10.20.0.0 0.0.255.255
permit ip 10.20.4.0 0.0.0.255 any
deny ip any any
!
route-map NAT_WW permit 10
match ip address NAT_ACL_WW
!
route-map NAT_3G permit 20
match ip address NAT_ACL_3G
VPN :ADSL_3G
crypto isakmp policy 1
encr 3des
hash md5
authentication pre-share
group 2
!
crypto isakmp key cvsrtmvpn96 address 85.234.65.57crypto isakmp identity hostname
crypto isakmp keepalive 15 10
!
crypto ipsec transform-set secure esp-3des esp-md5-hmac
!
!
crypto map mapping_3g 1 ipsec-isakmp
set peer 85.234.65.57
set security-association lifetime seconds 86400
set security-association idle-time 86400
set transform-set secure
match address VPN
!
ip access-list extended VPN
permit ip 10.20.4.0 0.0.0.255 any
!
ACCESS-LIST RULE :
ip access-list extended INTERNET
remark WAVEWORKS
permit ip 80.74.16.8 0.0.0.7 any
permit ip host 80.74.17.9 any
remark IPSEC_VPN
permit esp host 85.234.65.57 any
permit udp host 85.234.65.57 any eq isakmp
permit icmp host 85.234.65.57 any
remark ICMP
permit icmp any any administratively-prohibited
permit icmp any any echo-reply
permit icmp any any packet-too-big
permit icmp any any time-exceeded
permit icmp any any traceroute
permit icmp any any unreachable
remark NTP
permit udp host 80.74.16.30 any eq ntp
permit udp host 80.74.16.31 any eq ntp
remark DNS
permit udp any eq domain any
remark DENY_ALL
deny ip any any log
!
ip access-list extended LAN
remark DENY_BROADCASTS
deny ip any host 10.20.4.0
deny ip any host 10.20.4.255
deny ip host 0.0.0.0 any
remark PERMIT_ALL
permit ip 10.20.4.0 0.0.0.255 any
remark DENY_ALL
deny ip any any log
!
ip access-list standard TELNET_SSH
permit 80.74.17.9
permit 80.74.16.8 0.0.0.7
permit 10.20.4.0 0.0.0.255
!
line vty 0 4
access-class TELNET_SSH in
!
dialer-list 1 protocol ip permit
!
line 3
exec-timeout 0 0
script dialer mobile
LINUX VMG VPN PROFILE :
conn cvs161_3g
left=85.234.65.57
leftsubnet=0.0.0.0/0
right=0.0.0.0
rightid=@cvs161.waves.uk.net
rightsubnet=10.20.253.40/29
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
ikelifetime=24h
keylife=24h
keyingtries=3
pfs=no
rekey=yes
auto=start
dpdaction=restart
dpddelay=15
dpdtimeout=30
ipsec.secrets :
%any 85.234.65.57 : PSK “cvsrtmvpn96”
All Traffic will be forced to be sent down the tunnel including
INTERNET BREAK-OUT terminating at the Linux VM :
Linux VPN Profile
leftsubnet=0.0.0.0/0
right=0.0.0.0
Cisco Router VPN ACL set to :
ip access-list extended VPN
permit ip 10.20.4.0 0.0.0.255 any
This will cause all traffic to be pushed down the tunnel, even internet bound traffic.
Changes made to Linux terminating firewall
This will locally break-out sourced traffic to the internet :
iptables -t nat -I POSTROUTING 83 -o eth1 -s 10.20.4.0/24 -j MASQUERADE
!
route add –host 85.234.66.161 gw 85.234.65.57
!
This will provide HQ connectivity and block intersite connectivity as well
as allow internet access :
iptables -I FORWARD 46 -s 10.20.78.0/26 -d 10.20.0.0/24 -j ACCEPT
iptables -I FORWARD 47 -s 10.20.0.0/24 -d 10.20.78.0/26 -j ACCEPT
iptables -I FORWARD 48 -s 10.20.78.0/26 -d 10.20.0.0/16 -j DROP
iptables -I FORWARD 49 -s 10.20.0.0/16 -d 10.20.78.0/26 -j DROP
iptables -I FORWARD 50 -s 10.20.78.0/26 -j ACCEPT
iptables -I FORWARD 51 -d 10.20.78.0/26 -j ACCEPT
This is to allow HQ site to be able to establish connectivity over to remote site via
ipsec vpn tunnel
iptables -t nat -N 3g_access
sudo iptables -t nat -I POSTROUTING 85 -s 10.20.0.0/24 -j 3g_access
!
sudo iptables -t nat -I 3g_access 5 -d 10.20.78.0/26 -p icmp –icmp-type echo-request -j ACCEPT
sudo iptables -t nat -I 3g_access 6 -d 10.20.78.0/26 -j ACCEPT