Get the App
SLTechnology News&Howtos  ›  Network Security  › 

GNS3 configure Static P2P GRE over IPsec

Shulou Source: shulou.com Published: 2022-06-01 03:31:44 10月06日 Update

1. Experimental Topology

2. Basic network configuration

R1 configuration:

Interface FastEthernet0/0

Ip address 12.1.1.1 255.255.255.0

Interface FastEthernet1/0

Ip address 13.1.1.1 255.255.255.0

R2 configuration:

Interface FastEthernet0/0

Ip address 12.1.1.2 255.255.255.0

Interface FastEthernet1/0

Ip address 172.16.1.254 255.255.255.0

Ip route 0.0.0.0 0.0.0.0 12.1.1.1

R3 configuration:

Interface FastEthernet0/0

Ip address 13.1.1.3 255.255.255.0

Interface FastEthernet1/0

Ip address 192.168.1.254 255.255.255.0

Ip route 0.0.0.0 0.0.0.0 13.1.1.1

R4 configuration:

Interface FastEthernet0/0

Ip address 172.16.1.1 255.255.255.0

Ip route 0.0.0.0 0.0.0.0 172.16.1.254

R5 configuration:

Interface FastEthernet0/0

Ip address 192.168.1.1 255.255.255.0

Ip route 0.0.0.0 0.0.0.0 192.168.1.254

3. Configure Static P2P GRE over IPsec

3.1.Configuring GRE

R2 configuration:

Interface Tunnel2

Ip address 1.1.1.1 255.255.255.0

Tunnel source 12.1.1.2

Tunnel destination 13.1.1.3

R3 configuration:

Interface Tunnel3

Ip address 1.1.1.2 255.255.255.0

Tunnel source 13.1.1.3

Tunnel destination 12.1.1.2

3.2. configure LAN-TO-LAN × × (at this time, the ACL is different from the ordinary LAN-TO-LAN × ×)

R2 configuration:

Crypto isakmp policy 1

Encr 3des

Authentication pre-share

Group 2

Crypto isakmp key cisco123 address 13.1.1.3

Crypto ipsec transform-set ccie esp-3des esp-sha-hmac

Access-list 100 permit gre host 12.1.1.2 host 13.1.1.3

Crypto map mymap 1 ipsec-isakmp

Set peer 13.1.1.3

Set transform-set ccie

Match address 100

Interface FastEthernet0/0

Crypto map mymap

R3 configuration:

Crypto isakmp policy 1

Encr 3des

Authentication pre-share

Group 2

Crypto isakmp key cisco123 address 12.1.1.2

Crypto ipsec transform-set ccie esp-3des esp-sha-hmac

Access-list 100 permit gre host 13.1.1.3 host 12.1.1.2

Crypto map mymap 1 ipsec-isakmp

Set peer 12.1.1.2

Set transform-set ccie

Match address 100

Interface FastEthernet0/0

Crypto map mymap

3.3. Configure a dynamic routing protocol (in this case, all VPC traffic goes through tunnels. )

R2 configuration:

Router ospf 1

Network 1.1.1.0 0.0.0.255 area 0

Network 172.16.1.0 0.0.0.255 area 0

R3 configuration:

Router ospf 1

Network 1.1.1.0 0.0.0.255 area 0

Network 192.168.1.0 0.0.0.255 area 0

4. The influence of NAT on Static P2P GRE over IPsec

From the above, we can see that the intranet traffic goes through the GRE tunnel, so when NAT is applied in the physical port, it has no effect on Static P2P GRE over IPsec. However, when NAT is applied in Tunel port, the intranet segment must be excluded.

Tags: Configuration Traffic tunneling Application impact General dynamic Foundation difference Topology Physics Network Segment Network routing experiment Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Xiaomi Redmi vpn Docker Shulou Technology