Cisco IOS: How to Configure FlexVPN securing L2 Connections.

Overview

  • The flexVPN occur because traditional crypto maps is not sclabale, FlexVPN attaches IPsec directly to a Tunnel Interface.
  • Traditional site-to-site IPsec
LAN
 |
Router
 |
Crypto Map
 |
Physical Interface
 |
Internet
  • With Flex VPN we configure the Ipsec more scalable.
LAN
 |
Router
 |
Tunnel Interface
 |
IPsec Profile
 |
Physical Interface
 |
Internet
  • we can attach dynamic routing to this interface tunnel instead static routes.
  • Comparison ipsec FlexVPN vs Traditional IPsec
  • FlexVPN component configurations
IKEv2 Proposal
      ↓
IKEv2 Policy
      ↓
IKEv2 Keyring
      ↓
IKEv2 Profile
      ↓
IPsec Transform Set
      ↓
IPsec Profile
      ↓
Tunnel Interface
  • We can configure FLexVPN to secure L3 connection with routing or L2 connections.

Topology

Scenario

  1. configure the flexVPN between R16 and R5 to provide secure connectivity between LAN Server on branch and HQ servers.
  2. make tunnel connection using 100 id and password ikev2 is cisco.

Configurations

  • To configure L2 secure connection with FlexVPN, first we need to make the IPsec tunnel is up first and the second thing is we move to create pseudo tunnel between each site

Configuration Flex VPN R16

# define host to connect and the pre-share password
crypto ikev2 keyring R5
 peer R5
  address 10.10.100.5
  pre-shared-key cisco
 !
# define profile ikev2
crypto ikev2 profile R5-Ikev2
 match identity remote address 10.10.100.5 255.255.255.255
 identity local address 10.10.100.16
 authentication remote pre-share
 authentication local pre-share
 keyring local R5
 
# define profile ipsec
crypto ipsec profile R5
 set ikev2-profile R5-Ikev2
 
# create tunnel inteface vti in the Router
interface Tunnel100
 ip address 172.16.100.16 255.255.255.0
 tunnel source GigabitEthernet6
 tunnel destination 10.10.100.5
 tunnel protection ipsec profile R5

Configuration Flex VPN R5

# define host to connect and the pre-share password
crypto ikev2 keyring R16
 peer 10.10.100.16
  address 10.10.100.16
  pre-shared-key cisco
 !
 
# define profile ikev2
crypto ikev2 profile R16-Prof
 match identity remote address 10.10.100.16 255.255.255.255
 identity local address 10.10.100.5
 authentication remote pre-share
 authentication local pre-share
 keyring local R16
 
# define ipsec profile 
crypto ipsec profile R16-Ipsec
 set ikev2-profile R16-Prof
 
# define tunnel interface vti in the Router
interface Tunnel100
 ip address 172.16.100.5 255.255.255.0
 tunnel source GigabitEthernet3
 tunnel destination 10.10.100.16
 tunnel protection ipsec profile R16-Ipsec
end

Verification Tunnel and Ipsec is up

show crypto ikev2 sa
ping 172.16.100.16 source tunnel100

Configuration the L2TPv3 R5

pseudowire-class L2TP
 encapsulation l2tpv3
 ip local interface Tunnel100

default interface gi4
interface GigabitEthernet4
 xconnect 172.16.100.16 100 encapsulation l2tpv3 pw-class L2TP

Configuration the L2TPv3 R16

pseudowire-class L2TP
 encapsulation l2tpv3
 ip local interface Tunnel100

default interface gi1
interface GigabitEthernet1
 xconnect 172.16.100.5 100 encapsulation l2tpv3 pw-class L2TP

Verifications the tunnel L2

show xconnect all

Ping between same subnet from branch to HQ office

ping 192.168.100.4 source gigabitEthernet 0/2 repeat 100

Verifiy the IPsec tunnel is encrypted the packet in the R5 or R16

show crypto ipsec sa

Conclusions

  1. with FlexVPN we can secure the connection for L2 and L3.
  2. the FlexVPN make the architecture more scalable because we can also attach routing dyanmic to virtual interface.