Addressing Table
Objectives
In this lab, you will complete the following objectives:
- Part 1: Verify Connectivity
- Part 2: Review IPsec Parameters
- Part 3: Complete Remaining IPsec Tunnel Configurations
- Part 4: Verify IPsec VPN is Working
- Part 5: Easy VPN Server
Background / Scenario
In this activty, you will complete the site-to-site IPsec tunnel configuration and observe the function of a site-to-site IPsec tunnel between the SubstationRtr and MonitorRtr so the network traffic is encrypted between the substation and monitor networks. The router Gateway, in this example, acts as a pass-through and has no knowledge of the VPN. IPsec provides secure transmission of sensitive information over unprotected networks, such as the Internet. IPsec operates at the network layer and protects and authenticates IP packets between participating IPsec devices (peers), such as Cisco routers.
The Monitor and Substation LANs are not confgured to access the ExternalServer or the Remote LAN. Only the devices from the Monitor LAN end devices are allowed to access the DataHistorian. The traffic from the IT and Office LANs are blocked from accessing the DataHistorian by using access lists.
The Remote network is configured to allow the devices from the Office and IT networks via VPN. The VPN server is configured on RemoteRtr. All the end devices in this topology are allowed access to the ExternalServer.
Note: The understanding of the specific VPN configurations is beyond the intended scope of this lab.
Instructions
Part 1: Verify Connectivity
Step 1: Verify connectivity to ExternalServer.
- Navigate to any end device.
- From the command prompt, enter the command ping 209.165.200.254 (ExternalServer). All the pings should be successful.
C:/> ping 209.165.200.254 Pinging 209.165.200.254 with 32 bytes of data: Reply from 209.165.200.254: bytes=32 time<1ms TTL=125 Reply from 209.165.200.254: bytes=32 time=21ms TTL=125 Reply from 209.165.200.254: bytes=32 time<1ms TTL=125 Reply from 209.165.200.254: bytes=32 time=223ms TTL=125 Ping statistics for 209.165.200.254: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 223ms, Average = 61ms
Step 2: Verify connectivity between Monitor and Substation LANs.
- Navigate to MonitorWorkstation.
- Open a command prompt in the Desktop tab. Perform a traceroute to DataHistorian and note the path to DataHistorian.
C:/> tracert 192.168.23.240 Tracing route to 192.168.23.240 over a maximum of 30 hops: 1 70 ms 0 ms 202 ms 192.168.3.254 2 0 ms 7 ms 9 ms 10.2.2.1 3 0 ms 32 ms 0 ms 10.1.1.2 4 0 ms 115 ms 157 ms 192.168.23.240 Trace complete.
Step 3: Verify connectivity between other LANs.
- Verify connectivity between IT-PC and devices in the Monitor LAN, Substation LAN, and Office LAN. You will need to look up the IP address of each of the PCs and Workstations as they have dynamic IP addresses through DHCP.
- Ping from IT-PC to MonitorWorkstation
- Ping from IT-PC to EngineeringWS
- Ping from IT-PC to OfficePC
- There should be no connectivity between devices in the Remote LAN and device in the IT LAN, Monitor LAN, Substation LAN, and Office LAN. Test this by sending a ping from RemotePC to the following devices. You will need to look up the IP address of each of the PCs and Workstations as they have dynamic IP addresses through DHCP.
- Ping from RemotePC to IT-PC
- Ping from RemotePC to MonitorWorkstation
- Ping from RemotePC to EngineeringWS
- Ping from RemotePC to OfficePC
These pings should all succeed.
These pings should all fail.
Part 2: Review IPsec Parameters
Step 1: Review existing IPsec configurations on MonitorRtr.
Both MonitorRtr and SubstationRtr have been configured for an IPsec VPN that uses pre-shared key authentication, AES-256 encryption, and SHA for integrity.
Issue a show run command to review these configurations on MonitorRtr.
MonitorRtr# show run | begin crypto crypto isakmp policy 100 encryption aes 256 authentication pre-share group 5 ! crypto isakmp key VPNpass address 10.1.1.2 ! ! crypto ipsec transform-set VPN-SET esp-aes esp-sha-hmac ! crypto map VPN-MAP 100 ipsec-isakmp ! Incomplete set peer 10.1.1.2 set transform-set VPN-SET match address 100 <output omitted>
The table provides a description of each of these commands and their function.
Step 2: Review existing IPsec configurations on SubstationRtr.
The SubstationRtr will have similar commands to make it act as the other end of the IPsec tunnel.
Issue the show run | begin crypto command on SubstationRtr and compare the output to those from MonitorRtr in the previous step.
Part 3: Complete Remaining IPsec Tunnel Configurations
Step 1: Identify interesting traffic between SubstationRtr and MonitorRtr.
The IPsec configureations are completed, however “interesting” traffic must be defined so that the MonitorRtr will know what traffic should be encrypted. This is accomplished through an access list. Traffic that matches the access list, will be encrypted. The access list number, 100 in this example, is linked to the cypto map configurations by the match address 100 command seen in the show run output in the previosu part.
Configure ACL 100 to identify the traffic between the LAN on SubstationRtr and the LAN on MonitorRtr as interesting. This interesting traffic will trigger the IPsec VPN to be implemented when there is traffic between the SubstationRtr and MonitorRtr LANs. All other traffic sourced from the LANs will not be encrypted.
- Navigate to SubstationRtr. Configure an access list to identify interesting traffic on SubstationRtr.
- Navigate to MonitorRtr. Configure an access list to identify interesting traffic on MonitorRtr.
SubstationRtr# configure terminal SubstationRtr(config)# access-list 100 permit ip 192.168.22.0 0.0.1.255 192.168.3.0 0.0.0.255
MonitorRtr# configure terminal MonitorRtr(config)# access-list 100 permit ip 192.168.3.0 0.0.0.255 192.168.22.0 0.0.1.255
Step 2: Apply the crypto map to the router interface.
Finally, the IPsec configurations must be bound to an interface on the routers. This is accomplished with the crypto map command.
This command applies the crypto map named VPN-MAP to the selected interface. By doing so, the router uses the configurations within VPN-MAP (including the IPsec settings, peer address, and access list defining interesting traffic) to establish and maintain the VPN tunnel.
Applying a crypto map to an interface effectively enables IPsec VPN on that interface, meaning any outgoing traffic that matches the conditions specified in the crypto map (like the access list) will be encrypted and sent through the VPN tunnel.
Similarly, incoming traffic on this interface that matches the crypto map settings (such as from a specified VPN peer) will be decrypted and processed.
- Bind the crypto map to GigabitEthernet interface 0/0/0 on SubstationRtr.
- Bind the crypto map to GigabitEthernet interface 0/0/0 on MonitorRtr.
SubstationRtr(config)# interface GigabitEthernet0/0/0 SubstationRtr(config-if)# crypto map VPN-MAP SubstationRtr(config-if)# exit
MonitorRtr(config)# interface GigabitEthernet0/0/0 MonitorRtr(config-if)# crypto map VPN-MAP MonitorRtr(config-if)# exit
Part 4: Verify IPsec VPN is Working
Step 1: Verify the tunnel prior to sending interesting traffic.
Issue the show crypto ipsec sa command on MonitorRtr. Notice that the number of packets encapsulated, encrypted, decapsulated, and decrypted are all set to 0.
MonitorRtr# show crypto ipsec sa
interface: GigabitEthernet0/0/0
Crypto map tag: VPN-MAP, local addr 10.2.2.2
protected vrf: (none)
local ident (addr/mask/prot/port): (192.168.3.0/255.255.255.0/0/0)
remote ident (addr/mask/prot/port): (192.168.22.0/255.255.254.0/0/0)
current_peer 10.1.1.2 port 500
PERMIT, flags={origin_is_acl,}
#pkts encaps: 0, #pkts encrypt: 0, #pkts digest: 0
#pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0
<output omitted>
Step 2: Create interesting traffic.
Send a traceroute from MonitorWorkstation to DataHistorian. This traffic will cross the IPsec tunnel between MonitorRtr and SubstationRtr. It may take a couple of attempts for the trace to complete successfully.
C:/> tracert 192.168.23.240 Tracing route to 192.168.23.240 over a maximum of 30 hops: 1 197 ms 0 ms 292 ms 192.168.3.254 2 0 ms 20 ms 31 ms 10.1.1.2 3 0 ms 0 ms 302 ms 192.168.23.240 Trace complete.
Step 3: Verify the tunnel after interesting traffic.
On MonitorRtr, re-issue the show crypto ipsec sa command. Notice that the number of packets is more than 0, which indicates that the IPsec VPN tunnel is working.
MonitorRtr# show crypto ipsec sa
Crypto map tag: VPN-MAP, local addr 10.2.2.2
protected vrf: (none)
local ident (addr/mask/prot/port): (192.168.3.0/255.255.255.0/0/0)
remote ident (addr/mask/prot/port): (192.168.22.0/255.255.254.0/0/0)
current_peer 10.1.1.2 port 500
PERMIT, flags={origin_is_acl,}
#pkts encaps: 5, #pkts encrypt: 5, #pkts digest: 0
#pkts decaps: 3, #pkts decrypt: 3, #pkts verify: 0
Step 4: Send uninteresting traffic.
Now, send a trace to the OfficeServer (192.168.21.250) from the MonitorWorkstation. Because the destination 192.168.21.250 does not match the interesting traffic defined by access list 100, this traffic will not travel through the encrypted IPsec tunnel, but will rather be sent unencrypted across the Gateway router.
C:/> tracert 192.168.21.250 Tracing route to 192.168.21.250 over a maximum of 30 hops: 1 0 ms 0 ms 0 ms 192.168.3.254 2 0 ms 21 ms 0 ms 10.2.2.1 3 0 ms 0 ms 0 ms 10.1.1.2 4 52 ms 0 ms 9 ms 192.168.21.250 Trace complete.
Note: Traffic from Monitor LAN to the IT LAN or Office LAN is not interesting traffic. The traffic sourced from Substation LAN to the IT LAN or the Office LAN are also considered as uninteresting traffic.
Step 5: Verify the tunnel.
On MonitorRtr, re-issue the show crypto ipsec sa command. Notice that the number of packets has not changed, which verifies that uninteresting traffic is not encrypted.
MonitorRtr# show crypto ipsec sa
Crypto map tag: VPN-MAP, local addr 10.2.2.2
protected vrf: (none)
local ident (addr/mask/prot/port): (192.168.3.0/255.255.255.0/0/0)
remote ident (addr/mask/prot/port): (192.168.22.0/255.255.254.0/0/0)
current_peer 10.1.1.2 port 500
PERMIT, flags={origin_is_acl,}
#pkts encaps: 5, #pkts encrypt: 5, #pkts digest: 0
#pkts decaps: 3, #pkts decrypt: 3, #pkts verify: 0
Part 5: Easy VPN Server
In this part, you will finish the VPN configurations on RemoteRtr that allow users in the other LANs to access the Remote LAN. A RADIUS server will authenticate the remote users for access. Just like the previous part, the IPsec configurations are already applied. After the VPN configurations are complete, a remote user is able to access the Remote LAN using a VPN client.
AAA is already enabled RemoteRtr. Authentication requests are sent to a RADIUS server for verification.
Step 1: Verify connectivity.
Before establishing a VPN connection to the Remote network, there is no connectivity to RemoteSW, RemotePC, and RemoteServer.
From OfficePC, ping RemoteSW, RemotePC, and RemoteServer. All these pings will fail.
Step 2: Review RADIUS server configurations.
The RADIUS server is already configured with a username VPNuser and password VPNuserpass for VPN access to Remote network.
- Navigate to RemoteServer.
- From the Services tab, click AAA under the SERVICES heading. Review the network configuration and user account information configured on RemoteServer.
Step 3: Add RADIUS server for user authentication.
The enable mode password on RemoteRtr is class.
Configure RemoteRtr with the IP address and shared key ciscosecret used to access the RADIUS server.
RemoteRtr> enable Password: class RemoteRtr# configure terminal Enter configuration commands, one per line. End with CNTL/Z. RemoteRtr(config)# radius server EasyVPN RemoteRtr(config-radius-server)# address ipv4 172.16.30.250 auth-port 1645 RemoteRtr(config-radius-server)# key ciscosecret RemoteRtr(config-radius-server)# exit
Step 4: Apply the map.
Apply the map EasyVPNmap to the GigabitEthernet interface 0/0/0.
RemoteRtr(config)# interface g0/0/0 RemoteRtr(config-if)# crypto map EasyVPNmap *Jan 3 07:16:26.785: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is ON
Step 5: Establish VPN connection to RemoteRtr.
- Navigate to OfficePC. Ping RemoteRtr (64.100.1.2) to verify connectivity.
- From the Desktop tab, select VPN.
- Enter the following configured setting to establish the VPN connection.
- Click Connect to establish connection. Note: It may take a few attempts before establishing the VPN connection. When connected, a popup will appear with VPN is connected. Click OK to see the IP address assigned to VPN interface on the PC.
C:/> ping 64.100.1.2
GroupName: remoteoffice Group key: remoteoffice Host IP (Server IP): 64.100.1.2 Username: VPNuser Password: VPNuserpass
Step 6: Verify VPN connection.
The user credentials to access the switch are as follows:
Username: SSHuser
Password: SSHuserpass
From the command prompt, SSH into the RemoteSW.
C:/> ssh -l SSHuser 172.16.30.251 Password: RemoteSW#
While the VPN connection to the Remote LAN is active, you will be able to access the resources in the Remote LAN.
Answer Scripts
Router SubstationRtr
enable configure terminal access-list 100 permit ip 192.168.22.0 0.0.1.255 192.168.3.0 0.0.0.255 crypto isakmp policy 100 encr aes 256 authentication pre-share group 5 crypto isakmp key VPNpass address 10.2.2.2 crypto ipsec transform-set VPN-SET esp-aes esp-sha-hmac crypto map VPN-MAP 100 ipsec-isakmp set peer 10.2.2.2 set transform-set VPN-SET match address 100 interface GigabitEthernet0/0/0 crypto map VPN-MAP end
Router MonitorRtr
enable configure terminal access-list 100 permit ip 192.168.3.0 0.0.0.255 192.168.22.0 0.0.1.255 crypto isakmp policy 100 encr aes 256 authentication pre-share group 5 crypto isakmp key VPNpass address 10.1.1.2 crypto ipsec transform-set VPN-SET esp-aes esp-sha-hmac crypto map VPN-MAP 100 ipsec-isakmp set peer 10.1.1.2 set transform-set VPN-SET match address 100 interface GigabitEthernet0/0/0 crypto map VPN-MAP end
Router RemoteRtr
enable configure terminal crypto isakmp client configuration group remoteoffice key remoteoffice pool VPNCLIENTS netmask 255.255.255.0 interface GigabitEthernet0/0/0 crypto map mymap ip local pool VPNCLIENTS 10.1.1.100 10.1.1.200 radius server EasyVPN address ipv4 172.16.30.250 auth-port 1645 key ciscosecret end