Configuración VPN
Router 2811
switch 2950-24
Paso 1
Cable negro de switch a pc
switch (0): Fa0/1
Pc0: Fa0
Cable tipo rayo de router a switch
Router (0): Fa0/0
Switch (0): Fa0/2
Paso 2
Cable negro de switch a pc
Switch (1): Fa0/1
Pc1: Fa0
Cable tipo rayo de router a switch
Router (1): Fa0/0
Switch (1): Fa0/2
Paso 3
Cable punteado o cable de rayo de izq a derecha
Router (0):Fa0/1
Configuración PC0
IP: [Link]
Mascara: [Link]
Default Gateway: [Link]
Configuración PC1
IP: [Link]
Mascara: [Link]
Default Gateway: [Link]
Configuración Router 0
FastEthernet0/0
IP Address: [Link]
Subnet Mask: [Link]
Port Status: ON
FastEthernet0/1
IP Address: [Link]
Subnet Mask: [Link]
Port Status: ON
RIP
Network: [Link] add
Network: [Link] add
Configuración Router 1
FastEthernet0/0
IP Address: [Link]
Subnet Mask: [Link]
Port Status: ON
FastEthernet0/1
IP Address: [Link]
Subnet Mask: [Link]
Port Status: ON
RIP
Network: [Link] add
Network: [Link] add
Se verifica configuración VPN switch y PC
Luego de configurar los pasos anteriores damos doble click en el router 0 y vamos a la pestaña CLI
CLI ROUTER 0
Enable
Configuere terminal
crypto isakmp policy 10
authentication pre-share
hash sha
encryption aes 256
group 2
lifetime 86400
exit
crypto isakmp key toor address [Link] (router 1)
crypto ipsec transform-set TSET esp-aes esp-sha-hmac
access-list 101 permit ip [Link] [Link] [Link] [Link] (Direccion red 1 y red 2)
crypto map CMAP 10 ipsec-isakmp
set peer [Link] (Router 2)
match address 101
set transform-set TSET
exit
interface fa0/1 (Interface a Router 2)
crypto map CMAP
do wr
CLI ROUTER 1
Enable
Configuere terminal
crypto isakmp policy 10
authentication pre-share
hash sha
encryption aes 256
group 2
lifetime 86400
exit
crypto isakmp key toor address [Link] (router 0)
crypto ipsec transform-set TSET esp-aes esp-sha-hmac
access-list 101 permit ip [Link] [Link] [Link] [Link] (Dirección red 2 y red 1)
crypto map CMAP 10 ipsec-isakmp
set peer [Link] (Router 1)
match address 101
set transform-set TSET
exit
interface fa0/1 (Interface a Router 1)
crypto map CMAP
do wr
Comandos para ver encriptación y desencriptacion de archivos en Router (0) CLI y Router (1) CLI
en
show crypto isakmp sa
show crypto ipsec sa
[Link]