Configure Site to Site VPN on Cisco Routers using SDM
|
|
|
|
Introduction
This document explains how to configure Site to Site or Lan to Lan VPN
connection between two routers and it applies to Cisco 1800, 2800 and 3800
series Integrated Services Routers.
Back to Top
Requirements
To perform the steps described in this document, you need to have these
items:
Back to Top
Connect to Router using SDM
Open a web browser and type
http://
router-IP-address
in the Address field. Use the IP address
that you entered in field L6A of the LAN Addressing Worksheet. Press
Enter to launch SDM. For more information about how to launch
SDM, refer to
Configure
your Router with Security Device Manager.
Back to Top
Configure the Router using SDM
Follow these steps to setup Site to Site VPN on your
router:
-
Click Configure.
-
Click VPN.
-
Click Site-to-Site VPN from the VPN menu and
select Create a Site to Site VPN.
Click on Launch the selected task.
Two options gets displayed for Site to Site VPN configuration,
namely Quick setup and Step by step wizard in a new window.
Note: The Quick setup method uses SDM default parameters for the tunnel
whereas in Step by step wizard you can specify your own tunnel
parameters.
Quick Setup method to configure Site to Site VPN
Follow these steps to configure SDM using Quick Setup
Method.
-
Select Quick setup method and click
Next.
-
Follow these steps to enter the VPN Connection Information:
-
Select the interface of the local router for the VPN
connection.
-
Enter the remote peer router’s IP address.
-
Select the Authentication method.
-
Select the local router’s interface connected to the network or
device whose traffic is to be encrypted.
-
Enter the destination IP address and subnet mask where the
traffic terminates.
Click Next.
-
Check the summary of the configuration to be delivered to the
router.
Note: If you need to test the VPN connection after the configuration,
make sure that the peer router is configured properly. Select Test VPN
connectivity after configuring check box.
Click Finish.
-
A Confirmation Delivery Status window gets
displayed.
Click OK.
-
Click Start if you have selected the option Test
VPN connectivity after configuring. You get a confirmation message window if
the test is completed successfully.
Step by step method to configure Site to Site VPN
Follow these steps to configure SDM using Step by step
method:
-
Select Step by step wizard option to configure
site to site VPN.
Click Next.
-
Follow these steps to enter the VPN Connection Information:
-
Select the local router’s interface for VPN
connection.
-
Enter the remote peer router’s IP address.
-
Select the Authentication
method.
Click Next.
-
To manually configure IKE proposals click Add
else, click Next to use SDM default
proposals.
Configure the IKE policy by adding the necessary information in the
Add IKE Policy window and click
OK.
Note: The Add IKE Policy window gets displayed only when you click
Add.
Click Next.
-
Click Add to manually configure Transform sets
else, click Next to use SDM default transform
sets
Enter a name for the Transform set and the integrity and encryption
algorithm and click OK.
Note: The Edit Transform Set window gets displayed
only when you click on Add.
Click Next.
-
Select the traffic to be encrypted by using either of the two
methods:
In the first method:
In the second method:
-
Click Create/Select an access-list for IPSec
traffic to specify the type of traffic to be encrypted. Select
Create a new rule (ACL) from the drop down
menu.
-
Specify the name of the rule and its description in the
Add a Rule window.
Click Add.
-
Specify the details for the type of traffic to be protected in
Add an Extended Rule Entry.
Click OK.
-
To add more entries click Add else click
Next.
Click
OK.
-
Check the summary of the configuration to be delivered to the
router.
Note: If you need to test the VPN connection after the configuration,
make sure that the peer router is configured properly. Select Test VPN
connectivity after configuring check box.
Click Finish.
-
A Confirmation Delivery Status window gets
displayed.
Click OK.
-
Click Start if you have selected the option Test
VPN connectivity after configuring. You get a confirmation message window if
the test is completed successfully.
Back to Top
Next Step
You have now configured Site to Site VPN on your router.
To make further changes to your router, refer to the
Router Support
Page.
To configure other devices in your network, refer to the
Configuration
Overview Page.
To check your VPN connection, refer to
Verify
VPN connections on IOS Routers using CLI and SDM.
Back to Top
Troubleshoot the Procedure
This section provides information about common problems that you may
encounter. If this information does not solve your problem, contact the
SMB
Technical Assistance Center (SMB TAC) for assistance.
Back to Top
Related Information