Solved

Site-To-Site VPN with Cisco 887

Posted on 2014-03-05
2
2,175 Views
Last Modified: 2014-03-07
I have a client with Cisco 887 router on each site, and I need to create a vpn between sites, I have added this to my config, but no VPN works:

crypto isakmp key *VPNpsk#1 address XXX.XXX.XXX.XXX
!
!
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
 mode tunnel
!
!
!
crypto map SDM_CMAP_1 1 ipsec-isakmp
 description Tunnel to XXX.XXX.XXX.XXX
 set peer XXX.XXX.XXX.XXX
 set transform-set ESP-3DES-SHA
 match address 100
!
bridge irb

access-list 100 permit ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255
access-list 101 deny   ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255

any ideas, or working configs??
0
Comment
Question by:fns-netsys
2 Comments
 
LVL 22

Accepted Solution

by:
Jody Lemoine earned 500 total points
ID: 39909516
It's hard to say without seeing the entire configuration. Depending on how the rest of your configuration looks, you may be running into problems with NAT, external ACLs, &c.

If you're connecting a pair of IOS routers, you can simplify things a bit by using a virtual tunnel interface. This eliminates complexities with NAT and allows you to use standard routing.

Router 1:

crypto isakmp key *VPNpsk#1 address x.x.x.x no-xauth
!
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
!
crypto ipsec profile crypto-ipsec-pr-vti
 set transform-set ESP-3DES-SHA
!
interface Tunnel0
 ip address 192.168.255.0 255.255.255.254
 tunnel source Dialer1 (or whatever your outside interface is)
 tunnel mode ipsec ipv4
 tunnel destination x.x.x.x
 tunnel protection ipsec profile crypto-ipsec-pr-vti
!
ip route 192.168.2.0 255.255.255.0 Tunnel0

Router 2:

crypto isakmp key *VPNpsk#1 address x.x.x.x no-xauth
!
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
!
crypto ipsec profile crypto-ipsec-pr-vti
 set transform-set ESP-3DES-SHA
!
interface Tunnel0
 ip address 192.168.255.1 255.255.255.254
 tunnel source Dialer1 (or whatever your outside interface is)
 tunnel mode ipsec ipv4
 tunnel destination x.x.x.x
 tunnel protection ipsec profile crypto-ipsec-pr-vti
!
ip route 192.168.1.0 255.255.255.0 Tunnel0

Also, make sure that your access lists are allowing ISAKMP (500/udp) and ESP to reach the router.
0
 

Author Closing Comment

by:fns-netsys
ID: 39914229
Awesome, thank you so much! this worked flawlessly.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
VirtualBOX on GNS3 11 93
Allowing Multicast in the firewall 2 42
New TWC modem/router breaks network 53 67
Is WiFi half-duplex or Full -duplex 4 31
In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now