IPsec configuration

IPsec configuration

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
IPsec configuration Frank Winkler 05-03-2008
Posted by Frank Winkler on May 3, 2008, 4:48 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi there !

I have a working VPN setup (between a router and a PIX) based on crypto
maps. For education's sake, I tried to replace the crypto map ny a tunnel
interface on the router. Basically, it looks like this:


crypto map fw 101 ipsec-isakmp
set peer X
set transform-set vpn
match address 101

has been changed to

crypto ipsec profile vpn
set transform-set vpn
interface Tunnel1
no ip address
tunnel source FastEthernet0
tunnel destination X
tunnel mode ipsec ipv4
tunnel protection ipsec profile vpn


The ISAKMP part is left unchanged, the relevant parameters look comparable.
I'm aware that a route to the remote network is missing to make things work
but the problem is that the tunnel doesn't come up (see "show ip int
brief") so that the route is ignored.

What I'm wondering now is whether crypto maps and tunnel interfaces are
just different notations for the same thing (which would make them
interchangeable) or if they are completely different from each other. IOW:
can I use tunnel interfaces with a PIX or just with another tunnel
interface at the remote end?

TIA

        fw

Network Magic Graduation 20% off animated banner
Posted by Joe Beasley on May 3, 2008, 11:14 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Frank Winkler wrote:
> Hi there !
>
> I have a working VPN setup (between a router and a PIX) based on crypto
> maps. For education's sake, I tried to replace the crypto map ny a
> tunnel interface on the router. Basically, it looks like this:
>
>
> crypto map fw 101 ipsec-isakmp
> set peer X
> set transform-set vpn
> match address 101
>
> has been changed to
>
> crypto ipsec profile vpn
> set transform-set vpn
> interface Tunnel1
> no ip address
> tunnel source FastEthernet0
> tunnel destination X
> tunnel mode ipsec ipv4
> tunnel protection ipsec profile vpn
>
>
> The ISAKMP part is left unchanged, the relevant parameters look
> comparable. I'm aware that a route to the remote network is missing to
> make things work but the problem is that the tunnel doesn't come up (see
> "show ip int brief") so that the route is ignored.
>
> What I'm wondering now is whether crypto maps and tunnel interfaces are
> just different notations for the same thing (which would make them
> interchangeable) or if they are completely different from each other.
> IOW: can I use tunnel interfaces with a PIX or just with another tunnel
> interface at the remote end?
>
> TIA
>
> fw
The Virtual Tunnel Interface and the crypto map are not interchangeable.

Posted by Frank Winkler on May 4, 2008, 1:31 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Joe Beasley wrote:

>The Virtual Tunnel Interface and the crypto map are not interchangeable.

I see - and wh not? What's the technical difference?

Regards

        fw

Similar ThreadsPosted
Pix 501 VPN IPsec Configuration December 6, 2007, 11:51 pm
Cisco 803 IPsec configuration August 23, 2004, 11:14 am
Configuration reverted to previous configuration after power loss March 3, 2006, 11:14 am
IPsec within L2TP over IPsec - PIX. July 23, 2006, 6:14 pm
4506 acting as LNS with L2TP over IPsec and IPsec over L2TP. February 15, 2007, 5:47 pm
4506 acting as LNS with L2TP over IPsec and IPsec over L2TP. February 20, 2007, 4:00 am
PEAP Configuration Woes - PEAP configuration help December 19, 2005, 3:41 pm
PIX 501 Re-Configuration January 31, 2005, 4:08 am
Is this possible : VPN Configuration April 28, 2006, 12:26 am
PIX and BGP Configuration June 5, 2006, 5:17 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map