Case Learning: using VTI to solve the problem of dynamic IP Interconnection between Branch offices and headquarters
Requirements: the branch office (R1) has only ADSL lines and needs to exchange LAN visits with the headquarters (R3).
= R3murHQ =
Crypto keyring PSK
Pre-shared-key address 0.0.0.0 0.0.0.0 key cisco
Crypto ipsec transform-set TS esp-3des esp-sha-hmac
!
Crypto ipsec profile VTI
Set transform-set TS
Crypto isakmp profile DVTI
Keyring PSK
Match identity address 0.0.0.0
Virtual-template 1
Interface Virtual-Template1 type tunnel
Ip unnumbered Loopback0
Tunnel mode ipsec ipv4
Tunnel protection ipsec profile VTI
Interface Loopback0
Ip address 192.168.1.3 255.255.255.0
!
!
Interface Loopback100
Ip address 10.23.0.3 255.255.255.0
!
Interface GigabitEthernet0/0
Ip address 100.23.0.3 255.255.255.0
!
!
Router ospf 1
Network 10.23.0.0 0.0.0.255 area 0
Network 192.168.1.0 0.0.0.255 area 0
Ip route 0.0.0.0 0.0.0.0 100.23.0.2
= R1murBranch =
Crypto keyring PSK
Pre-shared-key address 0.0.0.0 0.0.0.0 key cisco
!
!
Crypto ipsec transform-set TS esp-3des esp-sha-hmac
!
Crypto ipsec profile VTI
Set transform-set TS
!
Interface Loopback0
Ip address 192.168.1.1 255.255.255.0
!
!
Interface Loopback100
Ip address 10.12.0.1 255.255.255.0
!
!
Interface Tunnel1
Ip unnumbered Loopback0
Tunnel source GigabitEthernet0/0
Tunnel mode ipsec ipv4
Tunnel destination 100.23.0.3
Tunnel protection ipsec profile VTI
!
Interface GigabitEthernet0/0
Ip address 100.12.0.1 255.255.255.0
!
Router ospf 1
Network 10.12.0.0 0.0.0.255 area 0
Network 192.168.1.0 0.0.0.255 area 0
!
Ip route 0.0.0.0 0.0.0.0 100.12.0.2