Site To Site VPN Cisco routers

Posted on 2007-03-29
Last Modified: 2008-12-06
Good Day Guys,

I would like to establish a VPN tunnel between 2 offices, both locations have Cisco 2811 routers with AIM-VPN/EPII - Plus on them. I need some recommendations of how to start a site - to - site VPN tunnel to make users on both locations to be able to access resources also on both locations securely ... I highly appreciate any help.

Question by:ndihelpiraq
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
  • +1

Accepted Solution

Louis_E earned 84 total points
ID: 18816678
This should get you started. 

You can also try the cisco SMD gui to conifigure it.
LVL 28

Assisted Solution

batry_boy earned 83 total points
ID: 18816698
Here is a configuration example of setting up an IPSEC tunnel between two routers:

However, I would also recommend looking at the SDM (web GUI) on each router to configure a site-to-site tunnel.  It will step you through the process of establishing the VPN connection between the two sites.  Here is some info on using the SDM for the VPN tunnel setup:
LVL 28

Expert Comment

ID: 18816712
Louis_E, you must type faster than me!  :)
Is your NGFW recommended by NSS Labs?

Ours is! NSS Labs Next Generation Firewall Test gives the WatchGuard Firebox M4600 a "Recommended" rating! Curious where your NGFW landed on the  Security Value Map? See the map and download the full report today!


Expert Comment

ID: 18816761
LOL yes i must do altough you typed more than me...
In my original post i meant SDM and not SMD sorry.

its a good start to get it up and running....a good tip is to turn on 'output commands before applying them so that you can see to config that is actually going onto the router. That way you lean the commands quicker.

Author Comment

ID: 18816913
Thank you guys very much for your prompt replies and the recommendations. I have used SDM many times before and will start using it once again in configuring the VPN Tunnel according to your recommendations. I hope that I can have it up and running soon, then I will get back to let you know.

Thanks again guys for the tips.

Assisted Solution

hancke earned 83 total points
ID: 18821237
If you run the wizard on SDM you will need to define a few basic things.
1. Both peer addresses (outside addresses)
2. Both inside subnets (host address if single host) You will define each end with source and destination.  This defines 'interesting traffic' that will go across the VPN.  You cannot use the same inside subnet at each site.
3. I usually use 3DES/MD5, Deffie-Hellman 2 and use PFS.
4. I use a 128 bit preshared key.
All else should be setup if the routers are currently installed and working.

Author Comment

ID: 18831508
I started working with the SDM but the problem is that it keeps telling me the that VPN is not available the same for the IPS, and it tells me to go to Cisco website ad update the IOS image on my router.

I'm currently using SDM 2.3.2 and my IOS Software version is 12.4(3e) ... shouldn't this software version have VPN, Firewall and IPS? ... Thoughts?

Thanks Again.

Author Comment

ID: 18832027
I just wanted to add the exact model number of the routers I have (CISCO2811-ADSL/ K9) with AIM-VPN/EPII - Plus on them but I don't know how to enable VPN and Firewall and IPS of course if they are available ... I actually don't know how to check ... any clues?

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Suggested Courses

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question