Site To Site VPN Cisco routers

Posted on 2007-03-29
Medium Priority
Last Modified: 2008-12-06
Good Day Guys,

I would like to establish a VPN tunnel between 2 offices, both locations have Cisco 2811 routers with AIM-VPN/EPII - Plus on them. I need some recommendations of how to start a site - to - site VPN tunnel to make users on both locations to be able to access resources also on both locations securely ... I highly appreciate any help.

Question by:ndihelpiraq
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
  • +1

Accepted Solution

Louis_E earned 336 total points
ID: 18816678
This should get you started.

You can also try the cisco SMD gui to conifigure it.
LVL 28

Assisted Solution

batry_boy earned 332 total points
ID: 18816698
Here is a configuration example of setting up an IPSEC tunnel between two routers:


However, I would also recommend looking at the SDM (web GUI) on each router to configure a site-to-site tunnel.  It will step you through the process of establishing the VPN connection between the two sites.  Here is some info on using the SDM for the VPN tunnel setup:

LVL 28

Expert Comment

ID: 18816712
Louis_E, you must type faster than me!  :)
Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.


Expert Comment

ID: 18816761
LOL yes i must do altough you typed more than me...
In my original post i meant SDM and not SMD sorry.

its a good start to get it up and running....a good tip is to turn on 'output commands before applying them so that you can see to config that is actually going onto the router. That way you lean the commands quicker.

Author Comment

ID: 18816913
Thank you guys very much for your prompt replies and the recommendations. I have used SDM many times before and will start using it once again in configuring the VPN Tunnel according to your recommendations. I hope that I can have it up and running soon, then I will get back to let you know.

Thanks again guys for the tips.

Assisted Solution

hancke earned 332 total points
ID: 18821237
If you run the wizard on SDM you will need to define a few basic things.
1. Both peer addresses (outside addresses)
2. Both inside subnets (host address if single host) You will define each end with source and destination.  This defines 'interesting traffic' that will go across the VPN.  You cannot use the same inside subnet at each site.
3. I usually use 3DES/MD5, Deffie-Hellman 2 and use PFS.
4. I use a 128 bit preshared key.
All else should be setup if the routers are currently installed and working.

Author Comment

ID: 18831508
I started working with the SDM but the problem is that it keeps telling me the that VPN is not available the same for the IPS, and it tells me to go to Cisco website ad update the IOS image on my router.

I'm currently using SDM 2.3.2 and my IOS Software version is 12.4(3e) ... shouldn't this software version have VPN, Firewall and IPS? ... Thoughts?

Thanks Again.

Author Comment

ID: 18832027
I just wanted to add the exact model number of the routers I have (CISCO2811-ADSL/ K9) with AIM-VPN/EPII - Plus on them but I don't know how to enable VPN and Firewall and IPS of course if they are available ... I actually don't know how to check ... any clues?

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Tired of waiting for your show or movie to load?  Are buffering issues a constant problem with your internet connection?  Check this article out to see if these simple adjustments are the solution for you.
Let’s list some of the technologies that enable smooth teleworking. 
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

764 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question