Networking-Blog

My WordPress Blog

Remote Site R.Config with explanations

– no service pad The packet assembler/disassembler (PAD) service supports X.25 links. This service is on by default, but it is not needed unless your router is using X.25.
  • Service timestamps debug/log uptime. // Log refers to syslog and debug is for debug output. The chosen option here was the syntax “uptime” which configures the debug and syslog output to also show the time since the device was booted. The other option would be ” service timestamps debug/log datetime“. Datetime configures the chosen option either log/debug to show output including the real local time / year / msecs this option isn’t chosen here though. Below is an example of the output:
“service timestamps log uptime”

Service password-encryption – Allows you to encrypt all passwords on your router so they cannot be easily guessed from your running-config. This command uses a very weak encryption because the router has to very quickly decode the passwords for its operation.

Boot-start/end-marker – The boot-start-marker and boot-end-marker flags, which can be seen in Cisco IOS software configuration files, are not CLI commands. These markers are written to configuration files automatically to flag the beginning and end of the boot commands (boot statements). By flagging boot statements, these markers allow the router to more reliably load Cisco IOS images during bootup

Logging buffered – See below for Cisco documentation.

Enable secret 5 – Sets an encrypted password for enable mode.

Enable password 7 – Enable secret takes precedence as it’s more secure:

——————————————————————————————————————–

aaa new-model – To enable AAA, you need to configure the aaa new-model command in global configuration.

aaa group server radius rad_eap + server 172.31.12.18 – Look below for cisco documentation and explanation.

aaa authentication login userlist local –

Login Authentication

You can use the aaa authentication login command to authenticate users who want exec access into the access server (tty, vty, console and aux).

Example 1: Exec Access with Radius then Local

Router(config)#aaa authentication login default group radius local

In the previous command:
  • The named list is the default one (default).
  • There are two authentication methods (group radius and local).

All users are authenticated with the Radius server (the first method). If the Radius server does not respond, then the router local database is used (the second method). For local authentication, define the username name and password:

Router(config)#username xxx password yyy

Because the list default in the aaa authentication login command is used, login authentication is automatically applied for all login connections (such as tty, vty, console and aux).

TBC…

Linux Zyxel Ipsec VPN Configuration

Zyxel Router Linux Config.

Phase 1 (IKE) = Lifetime   8Hrs
Phase 2 (IPSEC) = Keylife 24hrs

86400  = 24hrs = Seconds
28800  = 8hrs    = Seconds
1440     = 24hrs  = Minutes
480       = 8hrs     = Minutes

Linux Ipsec Directory Conf :

conn commtest
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
left= “Remote Peer Address”
leftsubnet= “Remote Subnet Address”
right=”Local Wan Address”
rightsubnet= “Local Subnet Address”
keyingtries=3
pfs=yes
rekey=yes
auto=start
keyexchange=ike
ikelifetime=8h
keylife=24h
dpdaction=restart
dpddelay=30
dpdtimeout=120

ipsec.secrets.conf

80.74.16.251 1.1.1.1 : PSK “commsvpn”
80.74.16.251 1.1.1.2 : PSK “commsvpn”
80.74.16.251 1.1.1.3 : PSK “commsvpn”
80.74.16.251 1.1.1.4 : PSK “commsvpn”
80.74.16.251 1.1.1.5 : PSK “commsvpn”

Rereadsecrets Command Forces OpenSWAN to reload the secrets from the ipsec.secrets file

sudo ipsec auto –rereadsecrets

Cisco sysopt

Allow packets from an IPsec tunnel and their payloads to bypass interface ACLs on the security appliance.
IPsec tunnels that are terminated on the security appliance are likely to fail if one of these commands is not enabled.

sysopt connection permit-ipsec
sysopt connection permit-vpn

Additional Commands :

show sysopt
show running-config sysopt