PHASE 1 IPSEC - DMVPN #4
PHASE 1 IPSEC - DMVPN
Alat dan Bahan :
- Laptop / PC
- EVE NG
DMVPN PHASE 1
DMVPN (Dynamic Multipoint Virtual Private Network), sekarang langsung masuk ke konfigurasi phase 1 yang selanjutnya yaitu menggunakan IPSec agar lebih secure
perhatikan topologi berikut :
HUB, SPOKE-1 & SPOKE-2
Router(config)#crypto isakmp policy 10
Router(config-isakmp)#authentication pre-share
Router(config-isakmp)#encryption aes128
Router(config-isakmp)#group 5
Router(config-isakmp)#hash sha
KONFIGURASI PEERING IPSEC (HUB & SPOKES)
HUB
Router(config)#crypto isakmp key idnmantab address 20.20.20.1
Router(config)#crypto isakmp key idnmantab address 30.30.30.1
SPOKE-1 & SPOKE-2
Router(config)#crypto isakmp key idnmantab address 10.10.10.1
Selanjutnya lakukan konfigurasi sebagaimana berikut:
HUB, SPOKE-1 & SPOKE-2
Router(config)#crypto ipsec transform-set idntransform esp-aes esp-shahmac
Router(cfg-crypto-trans)#mode transport
Router(config)#crypto ipsec profile idnprofile
Router(ipsec-profile)#set transform-set idntransform
Terakhir, tinggal kita masukkan konfigurasi Ipsec tadi ke Interface Tunnel
HUB, SPOKE-1 & SPOKE-2
Router(config)#int tun0
Router(config-if)#tunnel protect ipsec profile idnprofile
Komentar
Posting Komentar