Site To Site VPN Cisco routers

Good Day Guys,

I would like to establish a VPN tunnel between 2 offices, both locations have Cisco 2811 routers with AIM-VPN/EPII - Plus on them. I need some recommendations of how to start a site - to - site VPN tunnel to make users on both locations to be able to access resources also on both locations securely ... I highly appreciate any help.

Thanks,
ndihelpiraqAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Louis_ECommented:
This should get you started.
http://www.cisco.com/en/US/products/hw/routers/ps341/products_configuration_guide_book09186a008051522f.html 

You can also try the cisco SMD gui to conifigure it.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
batry_boyCommented:
Here is a configuration example of setting up an IPSEC tunnel between two routers:

http://www.cisco.com/en/US/products/hw/routers/ps274/products_configuration_example09186a008073e078.shtml

However, I would also recommend looking at the SDM (web GUI) on each router to configure a site-to-site tunnel.  It will step you through the process of establishing the VPN connection between the two sites.  Here is some info on using the SDM for the VPN tunnel setup:

http://www.cisco.com/en/US/products/sw/secursw/ps5318/products_user_guide_chapter09186a0080656460.html
0
batry_boyCommented:
Louis_E, you must type faster than me!  :)
0
The Ultimate Tool Kit for Technolgy Solution Provi

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy for valuable how-to assets including sample agreements, checklists, flowcharts, and more!

Louis_ECommented:
LOL yes i must do altough you typed more than me...
In my original post i meant SDM and not SMD sorry.

its a good start to get it up and running....a good tip is to turn on 'output commands before applying them so that you can see to config that is actually going onto the router. That way you lean the commands quicker.
0
ndihelpiraqAuthor Commented:
Thank you guys very much for your prompt replies and the recommendations. I have used SDM many times before and will start using it once again in configuring the VPN Tunnel according to your recommendations. I hope that I can have it up and running soon, then I will get back to let you know.

Thanks again guys for the tips.
0
hanckeCommented:
If you run the wizard on SDM you will need to define a few basic things.
1. Both peer addresses (outside addresses)
2. Both inside subnets (host address if single host) You will define each end with source and destination.  This defines 'interesting traffic' that will go across the VPN.  You cannot use the same inside subnet at each site.
3. I usually use 3DES/MD5, Deffie-Hellman 2 and use PFS.
4. I use a 128 bit preshared key.
All else should be setup if the routers are currently installed and working.
0
ndihelpiraqAuthor Commented:
I started working with the SDM but the problem is that it keeps telling me the that VPN is not available the same for the IPS, and it tells me to go to Cisco website ad update the IOS image on my router.

I'm currently using SDM 2.3.2 and my IOS Software version is 12.4(3e) ... shouldn't this software version have VPN, Firewall and IPS? ... Thoughts?

Thanks Again.
0
ndihelpiraqAuthor Commented:
I just wanted to add the exact model number of the routers I have (CISCO2811-ADSL/ K9) with AIM-VPN/EPII - Plus on them but I don't know how to enable VPN and Firewall and IPS of course if they are available ... I actually don't know how to check ... any clues?
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Routers

From novice to tech pro — start learning today.