Checklist for configuring site-to-site IPSec VPN

Last Updated : Nov 06, 2012 |
Prolog information
Use the following table to gather the information for simple Gateway site-to-site IPSec VPN.
Parameter
Possible values
Actual value
1. Type of connection to the ISP
  • ADSL
  • Cable Modem
2. VPN Interface
  • FastEthernet10/3
  • Serial port X/Y
3. VPN Local IP Address
Type:
  • Static
    – If static, provide:
    IP Address
    Mask
    Next-hop Router
  • Dynamic (DHCP/PPPoE)
4. Coordinating with the VPN Remote peer
a.) VPN IKE (Control) Phase 1 Parameters
— Encryption
  • des
  • 3des
  • aes
  • aes-192
  • aes-256
— Authentication Hash
  • sha
  • md5
— DH Group
  • 1
  • 2
  • 5
  • 14
— Lifetime seconds
  • 60 to 86,400 default: 86,400 (1 day)
b.) VPN IPSEC (Data) Phase 2 Parameters
— Encryption
  • esp-des
  • esp-3des
  • esp-aes
  • esp-aes-192
  • esp-aes-256
— Authentication Hash
  • esp-sha-hmac
  • esp-md5-hmac
— IP compression
  • enable (comp-lzs)
  • disable
— PFS Group
  • no pfs (default)
  • 1
  • 2
  • 5
  • 14
— Lifetime seconds
  • 120 to 86,400 default: 3,600 (1 hour)
— Lifetime kilobytes
  • 2,560 to 536,870,912 default: 4,608,000 kb
  • disable
5. Which packets should be secured
a. Protect rules matching options
  • IP source address
  • IP destination address
b. Bypass rules matching options
  • IP source address
  • IP destination address
  • udp
  • tcp
  • dscp
  • fragment
  • icmp
  • IP protocol
6. The remote peer (crypto isakmp peer) parameters
a. Remote peer
  • IP address
  • FQDN (dns name)
b. Pre-shared key
  • 1 to 127 alphanumerical characters. 1 to 64 bytes in hexadecimal notation
7. If the branch IP is dynamic
  • If the branch IP is an initiator, set initiate mode to none (device is a responder)
  • If the branch IP is a responder, set initiate mode to aggressive (device is an initiator)
  • Set self identity to identify the device in the remote peer