Incomplete Packet Tracer - Implement Access Control

Addressing Table

Device

Interface

IP Address

Subnet Mask

Default Gateway

Gateway

G0/0/0

10.1.1.1

255.255.255.252

N/A

G0/0/1

10.2.2.1

255.255.255.252

N/A

G0/0/2

209.165.201.1

255.255.255.224

N/A

ExternalServer

NIC

209.165.200.254

255.255.255.224

209.165.200.225

RemoteRtr

G0/0/0

64.100.1.2

255.255.255.224

N/A

G0/0/1

172.16.30.254

255.255.255.0

N/A

G0/0/2

209.165.200.226

255.255.255.224

N/A

RemoteSW

VLAN 1

172.16.30.251

255.255.255.0

172.16.30.254

RemoteServer

NIC

172.16.30.250

255.255.255.0

172.16.30.254

RemotePC

NIC

DHCP

MonitorRtr

G0/0/0

10.2.2.2

255.255.255.252

N/A

G0/0/1

192.168.2.254

255.255.255.0

N/A

G0/0/2

192.168.3.254

255.255.255.0

N/A

MonitorSW

VLAN 1

192.168..3.251

255.255.255.0

192.168.3.254

MonitorServer

NIC

192.168..3.250

255.255.255.0

192.168.3.254

MonitorWorkstation

NIC

DHCP

ITSwitch

VLAN 1

192.168.2.251

255.255.255.0

192.168.2.254

DNSServer

NIC

192.168.2.250

255.255.255.0

192.168.2.254

IT-PC

NIC

DHCP

SubstationRtr

G0/0/0

10.1.1.2

255.255.255.252

N/A

G0/0/1

192.168.21.254

255.255.254.0

N/A

G0/0/2

192.168.23.254

255.255.254.0

N/A

OfficeSW

VLAN 1

192.168.21.251

255.255.254.0

192.168.21.254

OfficeServer

NIC

192.168.21.250

255.255.254.0

192.168.21.254

OfficePC

NIC

DHCP

DataHistorian

VLAN 1

192.168.23.240

255.255.254.0

192.168.23.254

Objectives

In this lab, you will complete the following objectives:

  • Part 1: Verify Connectivity
  • Part 2: Review IPsec Parameters
  • Part 3: Complete Remaining IPsec Tunnel Configurations
  • Part 4: Verify IPsec VPN is Working
  • Part 5: Easy VPN Server

Background / Scenario

In this activty, you will complete the site-to-site IPsec tunnel configuration and observe the function of a site-to-site IPsec tunnel between the SubstationRtr and MonitorRtr so the network traffic is encrypted between the substation and monitor networks. The router Gateway, in this example, acts as a pass-through and has no knowledge of the VPN. IPsec provides secure transmission of sensitive information over unprotected networks, such as the Internet. IPsec operates at the network layer and protects and authenticates IP packets between participating IPsec devices (peers), such as Cisco routers.

The Monitor and Substation LANs are not confgured to access the ExternalServer or the Remote LAN. Only the devices from the Monitor LAN end devices are allowed to access the DataHistorian. The traffic from the IT and Office LANs are blocked from accessing the DataHistorian by using access lists.

The Remote network is configured to allow the devices from the Office and IT networks via VPN. The VPN server is configured on RemoteRtr. All the end devices in this topology are allowed access to the ExternalServer.

Note: The understanding of the specific VPN configurations is beyond the intended scope of this lab.

Instructions

Part 1: Verify Connectivity

Step 1: Verify connectivity to ExternalServer.

  1. Navigate to any end device.
  2. From the command prompt, enter the command ping 209.165.200.254 (ExternalServer). All the pings should be successful.
  3. C:/> ping 209.165.200.254
    
    Pinging 209.165.200.254 with 32 bytes of data:
    
    Reply from 209.165.200.254: bytes=32 time<1ms TTL=125
    Reply from 209.165.200.254: bytes=32 time=21ms TTL=125
    Reply from 209.165.200.254: bytes=32 time<1ms TTL=125
    Reply from 209.165.200.254: bytes=32 time=223ms TTL=125
    
    Ping statistics for 209.165.200.254:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 223ms, Average = 61ms

Step 2: Verify connectivity between Monitor and Substation LANs.

  1. Navigate to MonitorWorkstation.
  2. Open a command prompt in the Desktop tab. Perform a traceroute to DataHistorian and note the path to DataHistorian.
  3. C:/> tracert 192.168.23.240
    
    Tracing route to 192.168.23.240 over a maximum of 30 hops:
    
      1   70 ms     0 ms      202 ms    192.168.3.254
      2   0 ms      7 ms      9 ms      10.2.2.1
      3   0 ms      32 ms     0 ms      10.1.1.2
      4   0 ms      115 ms    157 ms    192.168.23.240
    
    Trace complete.

Step 3: Verify connectivity between other LANs.

  1. Verify connectivity between IT-PC and devices in the Monitor LAN, Substation LAN, and Office LAN. You will need to look up the IP address of each of the PCs and Workstations as they have dynamic IP addresses through DHCP.
    1. Ping from IT-PC to MonitorWorkstation
    2. Ping from IT-PC to EngineeringWS
    3. Ping from IT-PC to OfficePC

    These pings should all succeed.

  2. There should be no connectivity between devices in the Remote LAN and device in the IT LAN, Monitor LAN, Substation LAN, and Office LAN. Test this by sending a ping from RemotePC to the following devices. You will need to look up the IP address of each of the PCs and Workstations as they have dynamic IP addresses through DHCP.
    1. Ping from RemotePC to IT-PC
    2. Ping from RemotePC to MonitorWorkstation
    3. Ping from RemotePC to EngineeringWS
    4. Ping from RemotePC to OfficePC

    These pings should all fail.

Part 2: Review IPsec Parameters

Step 1: Review existing IPsec configurations on MonitorRtr.

Both MonitorRtr and SubstationRtr have been configured for an IPsec VPN that uses pre-shared key authentication, AES-256 encryption, and SHA for integrity.

Issue a show run command to review these configurations on MonitorRtr.

MonitorRtr# show run | begin crypto
crypto isakmp policy 100
 encryption aes 256
 authentication pre-share
 group 5
!
crypto isakmp key VPNpass address 10.1.1.2
!
!
crypto ipsec transform-set VPN-SET esp-aes esp-sha-hmac
!
crypto map VPN-MAP 100 ipsec-isakmp
 ! Incomplete
 set peer 10.1.1.2
 set transform-set VPN-SET
 match address 100
<output omitted>

The table provides a description of each of these commands and their function.

Command

Description

crypto isakmp policy 100

Defines an ISAKMP policy with priority level 100. Policies with lower numbers have higher priority. This policy will be used for VPN negotiations.

encryption aes 256

Specifies AES-256 as the encryption algorithm within the ISAKMP policy, providing a high level of security for encrypting data in the VPN tunnel.

authentication pre-share

Configures pre-shared key (PSK) authentication for ISAKMP. The PSK is shared between VPN peers for secure authentication during tunnel setup.

group 5

Sets Diffie-Hellman Group 5 (1536-bit key) for secure key exchange. Higher group numbers indicate stronger security but require more processing power.

crypto isakmp key VPNpass address 10.1.1.2

Configures a pre-shared key (VPNpass) for ISAKMP with the peer at IP address 10.1.1.2.(SubstationRtr) This shared key must match the key on the remote peer for the VPN connection to authenticate successfully.

crypto ipsec transform-set VPN-SET esp-aes esp-sha-hmac

Defines a transform set named VPN-SET for IPsec. This specifies how data should be secured within the VPN tunnel, using AES for encryption and SHA for data integrity.

crypto map VPN-MAP 100 ipsec-isakmp

Creates a crypto map named VPN-MAP with sequence number 100 and links it to IPsec with ISAKMP for VPN tunnel setup. The crypto map binds the VPN configurations to an interface, making the VPN operational.

set peer 10.1.1.2

Specifies the IP address of the VPN peer (10.1.1.2). This identifies the remote device to which the VPN tunnel will connect which is the SubstationRtr.

set transform-set VPN-SET

Associates the transform set VPN-SET with this crypto map, which specifies the security protocols and algorithms to secure data in the VPN tunnel.

match address 100

Links access list 100 to the crypto map, which defines the interesting traffic that should be encrypted and sent through the VPN. Only traffic matching this access list will initiate the VPN tunnel.

Step 2: Review existing IPsec configurations on SubstationRtr.

The SubstationRtr will have similar commands to make it act as the other end of the IPsec tunnel.

Issue the show run | begin crypto command on SubstationRtr and compare the output to those from MonitorRtr in the previous step.

Part 3: Complete Remaining IPsec Tunnel Configurations

Step 1: Identify interesting traffic between SubstationRtr and MonitorRtr.

The IPsec configureations are completed, however “interesting” traffic must be defined so that the MonitorRtr will know what traffic should be encrypted. This is accomplished through an access list. Traffic that matches the access list, will be encrypted. The access list number, 100 in this example, is linked to the cypto map configurations by the match address 100 command seen in the show run output in the previosu part.

Configure ACL 100 to identify the traffic between the LAN on SubstationRtr and the LAN on MonitorRtr as interesting. This interesting traffic will trigger the IPsec VPN to be implemented when there is traffic between the SubstationRtr and MonitorRtr LANs. All other traffic sourced from the LANs will not be encrypted.

  1. Navigate to SubstationRtr. Configure an access list to identify interesting traffic on SubstationRtr.
  2. SubstationRtr# configure terminal
    SubstationRtr(config)# access-list 100 permit ip 192.168.22.0 0.0.1.255 192.168.3.0 0.0.0.255
  3. Navigate to MonitorRtr. Configure an access list to identify interesting traffic on MonitorRtr.
  4. MonitorRtr# configure terminal
    MonitorRtr(config)# access-list 100 permit ip 192.168.3.0 0.0.0.255 192.168.22.0 0.0.1.255

Step 2: Apply the crypto map to the router interface.

Finally, the IPsec configurations must be bound to an interface on the routers. This is accomplished with the crypto map command.

This command applies the crypto map named VPN-MAP to the selected interface. By doing so, the router uses the configurations within VPN-MAP (including the IPsec settings, peer address, and access list defining interesting traffic) to establish and maintain the VPN tunnel.

Applying a crypto map to an interface effectively enables IPsec VPN on that interface, meaning any outgoing traffic that matches the conditions specified in the crypto map (like the access list) will be encrypted and sent through the VPN tunnel.

Similarly, incoming traffic on this interface that matches the crypto map settings (such as from a specified VPN peer) will be decrypted and processed.

  1. Bind the crypto map to GigabitEthernet interface 0/0/0 on SubstationRtr.
  2. SubstationRtr(config)# interface GigabitEthernet0/0/0
    SubstationRtr(config-if)# crypto map VPN-MAP
    SubstationRtr(config-if)# exit
  3. Bind the crypto map to GigabitEthernet interface 0/0/0 on MonitorRtr.
  4. MonitorRtr(config)# interface GigabitEthernet0/0/0
    MonitorRtr(config-if)# crypto map VPN-MAP
    MonitorRtr(config-if)# exit

Part 4: Verify IPsec VPN is Working

Step 1: Verify the tunnel prior to sending interesting traffic.

Issue the show crypto ipsec sa command on MonitorRtr. Notice that the number of packets encapsulated, encrypted, decapsulated, and decrypted are all set to 0.

MonitorRtr# show crypto ipsec sa

interface: GigabitEthernet0/0/0
Crypto map tag: VPN-MAP, local addr 10.2.2.2

protected vrf: (none)
local ident (addr/mask/prot/port): (192.168.3.0/255.255.255.0/0/0)
remote ident (addr/mask/prot/port): (192.168.22.0/255.255.254.0/0/0)
current_peer 10.1.1.2 port 500
PERMIT, flags={origin_is_acl,}
#pkts encaps: 0, #pkts encrypt: 0, #pkts digest: 0
#pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0

<output omitted>

Step 2: Create interesting traffic.

Send a traceroute from MonitorWorkstation to DataHistorian. This traffic will cross the IPsec tunnel between MonitorRtr and SubstationRtr. It may take a couple of attempts for the trace to complete successfully.

C:/> tracert 192.168.23.240
Tracing route to 192.168.23.240 over a maximum of 30 hops:

  1   197 ms    0 ms      292 ms    192.168.3.254
  2   0 ms      20 ms     31 ms     10.1.1.2
  3   0 ms      0 ms      302 ms    192.168.23.240

Trace complete.
Compare these traceroute results to the DataHistorian with the results from the previous part. Record any observable difference.
Answer Area
With the IPsec tunnel established, the route for interesting traffic does not include Gateway router at 10.2.2.1.

Step 3: Verify the tunnel after interesting traffic.

On MonitorRtr, re-issue the show crypto ipsec sa command. Notice that the number of packets is more than 0, which indicates that the IPsec VPN tunnel is working.

MonitorRtr# show crypto ipsec sa

Crypto map tag: VPN-MAP, local addr 10.2.2.2
protected vrf: (none)
local ident (addr/mask/prot/port): (192.168.3.0/255.255.255.0/0/0)
remote ident (addr/mask/prot/port): (192.168.22.0/255.255.254.0/0/0)
current_peer 10.1.1.2 port 500
PERMIT, flags={origin_is_acl,}
#pkts encaps: 5, #pkts encrypt: 5, #pkts digest: 0
#pkts decaps: 3, #pkts decrypt: 3, #pkts verify: 0

Step 4: Send uninteresting traffic.

Now, send a trace to the OfficeServer (192.168.21.250) from the MonitorWorkstation. Because the destination 192.168.21.250 does not match the interesting traffic defined by access list 100, this traffic will not travel through the encrypted IPsec tunnel, but will rather be sent unencrypted across the Gateway router.

C:/> tracert 192.168.21.250

Tracing route to 192.168.21.250 over a maximum of 30 hops:

  1   0 ms      0 ms      0 ms      192.168.3.254
  2   0 ms      21 ms     0 ms      10.2.2.1
  3   0 ms      0 ms      0 ms      10.1.1.2
  4   52 ms     0 ms      9 ms      192.168.21.250

Trace complete.

Note: Traffic from Monitor LAN to the IT LAN or Office LAN is not interesting traffic. The traffic sourced from Substation LAN to the IT LAN or the Office LAN are also considered as uninteresting traffic.

Step 5: Verify the tunnel.

On MonitorRtr, re-issue the show crypto ipsec sa command. Notice that the number of packets has not changed, which verifies that uninteresting traffic is not encrypted.

MonitorRtr# show crypto ipsec sa

Crypto map tag: VPN-MAP, local addr 10.2.2.2

protected vrf: (none)
local ident (addr/mask/prot/port): (192.168.3.0/255.255.255.0/0/0)
remote ident (addr/mask/prot/port): (192.168.22.0/255.255.254.0/0/0)
current_peer 10.1.1.2 port 500
PERMIT, flags={origin_is_acl,}
#pkts encaps: 5, #pkts encrypt: 5, #pkts digest: 0
#pkts decaps: 3, #pkts decrypt: 3, #pkts verify: 0

What will happen to the number of packets when using the Supervisory Workstation app on the Desktop of the MonitorWorkstation PC to access the DataHistorian? (User credentials: admin / admin) Note: The Supervisory Workstation may time out on the first attempt. For the charts to display correctly, enter the Substation cluster.
Answer Area
The number of packets should have increased because the traffic between DataHistorian and MonitorWorkstation is considered as interesting traffic and will go through the IPsec VPN tunnel.

Part 5: Easy VPN Server

In this part, you will finish the VPN configurations on RemoteRtr that allow users in the other LANs to access the Remote LAN. A RADIUS server will authenticate the remote users for access. Just like the previous part, the IPsec configurations are already applied. After the VPN configurations are complete, a remote user is able to access the Remote LAN using a VPN client.

AAA is already enabled RemoteRtr. Authentication requests are sent to a RADIUS server for verification.

Step 1: Verify connectivity.

Before establishing a VPN connection to the Remote network, there is no connectivity to RemoteSW, RemotePC, and RemoteServer.

From OfficePC, ping RemoteSW, RemotePC, and RemoteServer. All these pings will fail.

Step 2: Review RADIUS server configurations.

The RADIUS server is already configured with a username VPNuser and password VPNuserpass for VPN access to Remote network.

  1. Navigate to RemoteServer.
  2. From the Services tab, click AAA under the SERVICES heading. Review the network configuration and user account information configured on RemoteServer.

Step 3: Add RADIUS server for user authentication.

The enable mode password on RemoteRtr is class.

Configure RemoteRtr with the IP address and shared key ciscosecret used to access the RADIUS server.

RemoteRtr> enable
Password: class
RemoteRtr# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
RemoteRtr(config)# radius server EasyVPN
RemoteRtr(config-radius-server)# address ipv4 172.16.30.250 auth-port 1645
RemoteRtr(config-radius-server)# key ciscosecret
RemoteRtr(config-radius-server)# exit

Step 4: Apply the map.

Apply the map EasyVPNmap to the GigabitEthernet interface 0/0/0.

RemoteRtr(config)# interface g0/0/0
RemoteRtr(config-if)# crypto map EasyVPNmap
*Jan  3 07:16:26.785: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is ON

Step 5: Establish VPN connection to RemoteRtr.

  1. Navigate to OfficePC. Ping RemoteRtr (64.100.1.2) to verify connectivity.
  2. C:/> ping 64.100.1.2
  3. From the Desktop tab, select VPN.
  4. Enter the following configured setting to establish the VPN connection.
  5. GroupName:           remoteoffice
    Group key:           remoteoffice
    Host IP (Server IP): 64.100.1.2
    Username:            VPNuser
    Password:            VPNuserpass
  6. Click Connect to establish connection. Note: It may take a few attempts before establishing the VPN connection. When connected, a popup will appear with VPN is connected. Click OK to see the IP address assigned to VPN interface on the PC.
What is the assigned IP address for the VPN tunnel?
Answer Area
Your assigned IP address will be from the VPNCLIENTS pool (10.1.1.100 to 10.1.1.200).

Step 6: Verify VPN connection.

The user credentials to access the switch are as follows:

Username: SSHuser

Password: SSHuserpass

From the command prompt, SSH into the RemoteSW.

C:/> ssh -l SSHuser 172.16.30.251

Password: 


RemoteSW#

While the VPN connection to the Remote LAN is active, you will be able to access the resources in the Remote LAN.

Answer Scripts

Router SubstationRtr

enable
configure terminal
access-list 100 permit ip 192.168.22.0 0.0.1.255 192.168.3.0 0.0.0.255
crypto isakmp policy 100
 encr aes 256
 authentication pre-share
 group 5
crypto isakmp key VPNpass address 10.2.2.2
crypto ipsec transform-set VPN-SET esp-aes esp-sha-hmac
crypto map VPN-MAP 100 ipsec-isakmp
 set peer 10.2.2.2
 set transform-set VPN-SET
 match address 100
interface GigabitEthernet0/0/0
 crypto map VPN-MAP
end

Router MonitorRtr

enable
configure terminal
access-list 100 permit ip 192.168.3.0 0.0.0.255 192.168.22.0 0.0.1.255
crypto isakmp policy 100
 encr aes 256
 authentication pre-share
 group 5
crypto isakmp key VPNpass address 10.1.1.2
crypto ipsec transform-set VPN-SET esp-aes esp-sha-hmac
crypto map VPN-MAP 100 ipsec-isakmp
 set peer 10.1.1.2
 set transform-set VPN-SET
 match address 100
interface GigabitEthernet0/0/0
 crypto map VPN-MAP
end

Router RemoteRtr

enable
configure terminal
crypto isakmp client configuration group remoteoffice
 key remoteoffice
 pool VPNCLIENTS
 netmask 255.255.255.0
interface GigabitEthernet0/0/0
 crypto map mymap
ip local pool VPNCLIENTS 10.1.1.100 10.1.1.200
radius server EasyVPN
 address ipv4 172.16.30.250 auth-port 1645
 key ciscosecret
end

© 2024 - 2025 Cisco and/or its affiliates. All rights reserved. Cisco Public