Professional Documents
Culture Documents
Sau khi trnh by v l thuyt ca IPsec VPN trong cc bi vit Tng quan v cng ngh
VPN v Tng quan v IPsec VPN, trong bi vit ny chng ta s i vo phn trin khai IPsec VPN,
c th l cu hnh site-to-site VPN trn Cisco ASA.
Ta s s dng m hnh sau:
enable outside1
policy 2
authentication pre-share
encryption 3des
hash md5
group 2
lifetime 3600
TO_BRANCH
TO_BRANCH
TO_BRANCH
TO_BRANCH
1
1
1
1
TO_CENTRAL
TO_CENTRAL
TO_CENTRAL
TO_CENTRAL
1
1
1
1
Ch rng lifetime c Phase 1 v Phase 2 khng cn phi ging nhau gia 2 VPN peers, m
chng s t thng lng s dng gi tr no nh hn. Ngoi ra, trn ASA2 v c translation rule
dng NAT cc traffic i t cng inside ra outside l interface p crypto map nn ta phi
cu hnh Identity NAT khng NAT cc traffic c a qua VPN tunnel (trn ASA1 khng cn v
khng c translation rule no dng NAT traffic i t cng inside ra outside1 l interface p
crypto map):
Thc hin bt gi tin bng Wireshark, ta thy cn tng cng 6 gi tin thng lng xong Phase
1 Main Mode, v sau thng lng Phase 2 Quick Mode cn thm 3 gi tin na. Cc gi tin
tip theo (ESP) l traffic ca PC1 gi n PC2 c m ha bi VPN tunnel:
Xem thng tin tunnel ca Phase 1 bng lnh show crypto ikev1 sa detail
Xem thng tin tunnel ca Phase 2 bng lnh show crypto ipsec sa detail
Xem thng tin tm tt tunnel ca c Phase 1 v Phase 2 bng lnh show vpn-sessiondb l2l
Nu nh cc bn cu hnh site-to-site VPN trn Cisco router th thc hin nh sau (gi s trong m
hnh trn thay ASA2 bng router R2, v interface f0/0 ca R2 kt ni vi ISP2):