Site-To-Site Vpn Using An Ipsec Tunnel And Gre - Cisco 1941W Configuration Manual

Cisco 3900 series, cisco 2900 series, cisco 1900 series
Hide thumbs Also See for 1941W:
Table of Contents

Advertisement

Chapter
Configuring Security Features
The Cisco Easy VPN client feature supports configuration of only one destination peer. If your
Note
application requires creation of multiple VPN tunnels, you must manually configure the IPSec VPN and
Network Address Translation/Peer Address Translation (NAT/PAT) parameters on both the client and the
server.
Cisco 3900 series, 2900 series, and 1900 series ISRs can be also configured to act as Cisco Easy VPN
servers, letting authorized Cisco Easy VPN clients establish dynamic VPN tunnels to the connected
network. For information on configuring Cisco Easy VPN servers, see the
http://www.cisco.com/en/US/docs/ios/12_2t/12_2t8/feature/guide/ftunity.html.
Site-to-Site VPN Example
The configuration of a site-to-site VPN uses IPSec and the generic routing encapsulation (GRE) protocol
to secure the connection between the branch office and the corporate network.
deployment scenario.
Figure 2
1
Branch office containing multiple LANs and VLANs
2
Fast Ethernet LAN interface—With address 192.165.0.0/16 (also the inside interface for NAT)
3
VPN client—Cisco 3900 series, 2900 series, or 1900 series ISR
4
Fast Ethernet or ATM interface—With address 200.1.1.1 (also the outside interface for NAT)
5
LAN interface—Connects to the Internet; with outside interface address of 210.110.101.1
6
VPN client—Another router, which controls access to the corporate network
7
LAN interface—Connects to the corporate network; with inside interface address of 10.1.1.1
8
Corporate office network
9
IPSec tunnel with GRE
For more information about IPSec and GRE configuration, see the
IPSec"
http://www.cisco.com/en/US/docs/ios/sec_secure_connectivity/configuration/guide/12_4t/
sec_secure_connectivity_12_4t_book.html.
Configuration Examples
Each example configures a VPN over an IPSec tunnel, using the procedure given in the
VPN over an IPSec Tunnel" section on page
configuration is given, followed by the specific procedure for a site-to-site configuration.
Cisco 3900 Series, Cisco 2900 Series, and Cisco 1900 Series Integrated Services Routers Generation 2 Software Configuration Guide

Site-to-Site VPN Using an IPSec Tunnel and GRE

3
2
4
1
chapter of
Cisco IOS Security Configuration Guide: Secure Connectivity, Release 12.4T
6
5
Internet
9
134. Then, the specific procedure for a remote access
Configuring VPN
Easy VPN Server
Figure 2
shows a typical
8
7
Configuring Security for VPNs with
"Configure a
feature at:
at:
133

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

194129012911295139252921 ... Show all

Table of Contents