[ROUTER-0]-----[ROUTER-1]
[ROUTER-0]-----[ROUTER-2]
[ROUTER-0]-----[ROUTER-3]
[ROUTER-1] is the NHRP server.
[ROUTER-2] and [ROUTER-3] are the NHRP clients.
[ROUTER-0] fa0/1: 192.168.1.254/24
[ROUTER-0] fa0/2: 192.168.2.254/24
[ROUTER-0] fa0/3: 192.168.3.254/24
[ROUTER-1] fa0/0: 192.168.1.1/24
[ROUTER-2] fa0/0: 192.168.2.2/24
[ROUTER-3] fa0/0: 192.168.3.3/24
ROUTER-1 configuration
Network
ROUTER-1(config)#interface FastEthernet0/0ROUTER-1(config-if)#ip address 192.168.1.1 255.255.255.0ROUTER-1(config)#ip route 0.0.0.0 0.0.0.0 192.168.1.254
Multipoint GRE (mGRE) and Next Hop Resolution Protocol (NHRP)
ROUTER-1(config)#interface Tunnel1ROUTER-1(config-if)#ip address 1.2.3.1 255.255.255.0ROUTER-1(config-if)#ip nhrp authentication NHRP_KEYROUTER-1(config-if)#ip nhrp map multicast dynamicROUTER-1(config-if)#ip nhrp network-id 123ROUTER-1(config-if)#tunnel source FastEthernet0/0ROUTER-1(config-if)#tunnel mode gre multipointROUTER-1(config-if)#tunnel key 123
IPsec
ROUTER-1(config)#crypto isakmp policy 1ROUTER-1(config-isakmp)#authentication pre-shareROUTER-1(config-isakmp)#encryption aesROUTER-1(config-isakmp)#hash shaROUTER-1(config-isakmp)#group 2ROUTER-1(config-isakmp)#lifetime 86400ROUTER-1(config)#crypto isakmp aggressive-mode disableROUTER-1(config)#crypto isakmp key SECRET_KEY address 192.168.2.2ROUTER-1(config)#crypto isakmp key SECRET_KEY address 192.168.3.3ROUTER-1(config)#crypto isakmp enableROUTER-1(config)#crypto ipsec transform-set TRANSFORM_SET esp-aes esp-sha-hmacROUTER-1(config)#crypto ipsec profile PROFILEROUTER-1(ipsec-profile)#set transform-set TRANSFORM_SETROUTER-1(ipsec-profile)#set pfs group2ROUTER-1(config)#interface Tunnel1ROUTER-1(config-if)#tunnel protection ipsec profile PROFILE
ROUTER-2 configuration
Network
ROUTER-2(config)#interface FastEthernet0/0ROUTER-2(config-if)#ip address 192.168.2.2 255.255.255.0ROUTER-2(config)#ip route 0.0.0.0 0.0.0.0 192.168.2.254
Multipoint GRE (mGRE) and Next Hop Resolution Protocol (NHRP)
ROUTER-2(config)#interface Tunnel2ROUTER-2(config-if)#ip address 1.2.3.2 255.255.255.0ROUTER-2(config-if)#ip nhrp authentication NHRP_KEYROUTER-2(config-if)#ip nhrp map 1.2.3.1 192.168.1.1ROUTER-2(config-if)#ip nhrp network-id 123ROUTER-2(config-if)#ip nhrp nhs 1.2.3.1ROUTER-2(config-if)#tunnel source FastEthernet0/0ROUTER-2(config-if)#tunnel mode gre multipointROUTER-2(config-if)#tunnel key 123
IPsec
ROUTER-2(config)#crypto isakmp policy 1ROUTER-2(config-isakmp)#authentication pre-shareROUTER-2(config-isakmp)#encryption aesROUTER-2(config-isakmp)#hash shaROUTER-2(config-isakmp)#group 2ROUTER-2(config-isakmp)#lifetime 86400ROUTER-2(config)#crypto isakmp aggressive-mode disableROUTER-2(config)#crypto isakmp key SECRET_KEY address 192.168.1.1ROUTER-2(config)#crypto isakmp enableROUTER-2(config)#crypto ipsec transform-set TRANSFORM_SET esp-aes esp-sha-hmacROUTER-2(config)#crypto ipsec profile PROFILEROUTER-2(ipsec-profile)#set transform-set TRANSFORM_SETROUTER-2(ipsec-profile)#set pfs group2ROUTER-2(config)#interface Tunnel2ROUTER-2(config-if)#tunnel protection ipsec profile PROFILE
ROUTER-3 configuration
Network
ROUTER-3(config)#interface FastEthernet0/0ROUTER-3(config-if)#ip address 192.168.3.3 255.255.255.0ROUTER-3(config)#ip route 0.0.0.0 0.0.0.0 192.168.3.254
Multipoint GRE (mGRE) and Next Hop Resolution Protocol (NHRP)
ROUTER-3(config)#interface Tunnel3ROUTER-3(config-if)#ip address 1.2.3.3 255.255.255.0ROUTER-3(config-if)#ip nhrp authentication NHRP_KEYROUTER-3(config-if)#ip nhrp map 1.2.3.1 192.168.1.1ROUTER-3(config-if)#ip nhrp network-id 123ROUTER-3(config-if)#ip nhrp nhs 1.2.3.1ROUTER-3(config-if)#tunnel source FastEthernet0/0ROUTER-3(config-if)#tunnel mode gre multipointROUTER-3(config-if)#tunnel key 123
IPsec
ROUTER-3(config)#crypto isakmp policy 1ROUTER-3(config-isakmp)#authentication pre-shareROUTER-3(config-isakmp)#encryption aesROUTER-3(config-isakmp)#hash shaROUTER-3(config-isakmp)#group 2ROUTER-3(config-isakmp)#lifetime 86400ROUTER-3(config)#crypto isakmp aggressive-mode disableROUTER-3(config)#crypto isakmp key SECRET_KEY address 192.168.1.1ROUTER-3(config)#crypto isakmp enableROUTER-3(config)#crypto ipsec transform-set TRANSFORM_SET esp-aes esp-sha-hmacROUTER-3(config)#crypto ipsec profile PROFILEROUTER-3(ipsec-profile)#set transform-set TRANSFORM_SETROUTER-3(ipsec-profile)#set pfs group2ROUTER-3(config)#interface Tunnel3ROUTER-3(config-if)#tunnel protection ipsec profile PROFILE
Troubleshooting commands
Router#show ip nhrpRouter#show dmvpnRouter#show crypto isakmp saRouter#show crypto ipsec sa
No comments:
Post a Comment