Hey, Mr. OG! You have changed many lives, mine included. Now I work with advanced networks, and a new thing (for me) can benefit from your amazing style of teaching. IPsec tunnels dual encryption using CA signed certificates. Don't even know where to start making even a lab for this. Different vendor devices participate in this type of layered security architecture. I am quite sure you know already. Guidance much much appreciated 😊
Although the routers can ping each other’s tunnel interfaces - R1 still requires an appropriate destination-route pointing down the tunnel for the /24 network at R2 (and vice versa). Without them, traffic will be default-routed in the clear to the gateway, which of course doesn’t guarantee it making it past the gateway. Great vid!
Great explanation. Sometimes you can read about a topic, think you understand it, but there are grey areas between the components. This really helps put it all together in my head. Thanks!!
you are just awsome hats off and you deserve a salute, you explain and draft the lab in the most simplified /detailed and summarize way it is realy amazing
Watchig this video on 4/11/2022. I also watch your videos on CBT nuggets. great teacher I appreciate your efforts for network engineers community, i study online. Thanks
Thank you for the content! Two items for feedback. One, I would have liked to see the IPSec profile creation because that is the part I struggle to remember. Two, I dig the new "lipstick" cam but it was tracking your face at times and that was slightly distracting. Just my views and wanted to share! Thank you again for sharing your knowledge with us!
Hey Keith - Great video. I am just trying to create a IPSec VPN tunnel in between two Asus routers. Can you please guide on how to create this VPN tunnel?
Looking at 3:22 clearly there's no route from 10.2.0.0 to 10.1.0.0 other than the default "internet" route, therefore it won't go through the tunnel. Just as many comments already pointed, it will need a route (something like #ip route 10.1.0.0 255.255.255.0 10.12.12.2)
The traffic won't be forwarded unless a static route or a dynamic routing protocol is configured on both Routers so that the Routers will know/learn where to send the traffic. Thanks Keith
Thank you, @theotherguy6155, for letting me know. If you go to my channel, and use the search from there, along with the keyword or topic you are looking for, that may help you to find the content you are looking for.
Great video! Extremely helpful for some troubleshooting I have to do this coming week! Glad I found this. One thing I am having trouble with is configuring an ipsec profile on my router. Can you point me to video where this is explained by any chance?
Hi, I couldn't find any from Keith regarding the ipsec profile configuration but I found another video that might help: th-cam.com/video/xZrzcJxla4o/w-d-xo.htmlfeature=shared
Thank you for the question ARSHAM EQ. I have a license for CML personal edition (from Cisco), but often use Eve-NG. Both get the job done for most of what I am working on.
PC1 to PC2 bound (vice versa) traffic will work and be protected via GRE / IPSec tunnel. Why and how? GRE Tunnel is up. Both Tunnel interfaces have reachability. Question for you Keith - which emulation software was used for packet capture? Thanks!
you have missed an important point (Routing), therefore the traffic won't be forwarded unless a static route or dynamic routing protocol is configured on both Routes so that the Routers will now where to send the traffic.
@@mehdifar995 ping worked because Keith pinged an IP Adresse which belongs to a connected network 10.12.12.0/24 for connected networks we don't need neither static route nor dynamic routing protocol for the Router to know where to send the packet to. Regards
Thank you for the question Rene Gonzalez. This is one of several ways to implement an IPsec VPN tunnel. The fancy name for it is a Virtual Tunnel Interface (VTI). More VPN videos coming. Get subscribed, and stay tuned for more.
Thank you very much for your explanation, the colours used makes it really easy to visualise and undertsand the concept. Love your videos too! Just wanted to add on for those who are wondering for the ipsec profile configuration, I found this video that might help: th-cam.com/video/xZrzcJxla4o/w-d-xo.htmlfeature=shared
Hey, Mr. OG!
You have changed many lives, mine included.
Now I work with advanced networks, and a new thing (for me) can benefit from your amazing style of teaching. IPsec tunnels dual encryption using CA signed certificates. Don't even know where to start making even a lab for this. Different vendor devices participate in this type of layered security architecture. I am quite sure you know already. Guidance much much appreciated 😊
Thank you Kai Hu! And congratulations on all your accomplishments over the years!!!
All the best.
you are one of the top teacher i have seen so far on the youtube stay blessed
Although the routers can ping each other’s tunnel interfaces - R1 still requires an appropriate destination-route pointing down the tunnel for the /24 network at R2 (and vice versa). Without them, traffic will be default-routed in the clear to the gateway, which of course doesn’t guarantee it making it past the gateway. Great vid!
Thank you John! Spot on. Appreciate you taking time for the comments. More videos to come.
Great explanation. Sometimes you can read about a topic, think you understand it, but there are grey areas between the components. This really helps put it all together in my head. Thanks!!
Thank you @TheWextin!
you are just awsome hats off and you deserve a salute, you explain and draft the lab in the most simplified /detailed and summarize way it is realy amazing
Watchig this video on 4/11/2022. I also watch your videos on CBT nuggets.
great teacher I appreciate your efforts for network engineers community, i study online. Thanks
Thank you Lannet Solutions!
Keith I'm watching your videos on the Network + .. YOU ROCK !!!
Thank you Afakh Patel!
You are the best!! Your youtube channel should have more subscribers!!
Maybe one day!
Thank you for the content! Two items for feedback. One, I would have liked to see the IPSec profile creation because that is the part I struggle to remember. Two, I dig the new "lipstick" cam but it was tracking your face at times and that was slightly distracting. Just my views and wanted to share! Thank you again for sharing your knowledge with us!
Yes, it would be great to see the ISAKMP & IPSEC part of the config file....@Keith Barker please show us!
Noted, thank you Wayne!
a pleasure to hear your explanation
Thank you Mehdi Hamid!
now i will watch and recomend your channel
Hey Keith - Great video. I am just trying to create a IPSec VPN tunnel in between two Asus routers. Can you please guide on how to create this VPN tunnel?
Thank you for the suggestion @Unknown-w4d3r❗
So interesting, keith!
Thank you!
Looking at 3:22 clearly there's no route from 10.2.0.0 to 10.1.0.0 other than the default "internet" route, therefore it won't go through the tunnel. Just as many comments already pointed, it will need a route (something like #ip route 10.1.0.0 255.255.255.0 10.12.12.2)
Thank you Andrei Craciun! Perfectly correct.
Andre, thanks for the help with that.
The traffic won't be forwarded unless a static route or a dynamic routing protocol is configured on both Routers so that the Routers will know/learn where to send the traffic.
Thanks Keith
Thank you Ibrahim Alazawi! Perfectly correct. More vids to come.
Thanks Keith, another well explained educational video. 😀
Thanks 👍
you have so many videos it's impossible to find the one after this you've alluded too
Thank you, @theotherguy6155, for letting me know.
If you go to my channel, and use the search from there, along with the keyword or topic you are looking for, that may help you to find the content you are looking for.
Thank you Keith this was a very well explained video, I appreciate it
Very welcome
we need your more videos on fortinet and on paloalto
Great video! Extremely helpful for some troubleshooting I have to do this coming week! Glad I found this. One thing I am having trouble with is configuring an ipsec profile on my router. Can you point me to video where this is explained by any chance?
Hi, I couldn't find any from Keith regarding the ipsec profile configuration but I found another video that might help: th-cam.com/video/xZrzcJxla4o/w-d-xo.htmlfeature=shared
Hi Keith, what simulation program are you using these days for your demonstrations and labs? VIRL 199$?
Thank you for the question ARSHAM EQ. I have a license for CML personal edition (from Cisco), but often use Eve-NG. Both get the job done for most of what I am working on.
Fabulous content like always
Thank you sina e!
Well done
Thank you S76!
Great use of color. Of the many different parts of the configuration, the colors help separate and focus on them as you’re presenting.
Thanks so much!
about the last question, so where is the video that is going to discuss it? a little confusing as you have a ton of very insightful videos =)
PC1 to PC2 bound (vice versa) traffic will work and be protected via GRE / IPSec tunnel. Why and how? GRE Tunnel is up. Both Tunnel interfaces have reachability.
Question for you Keith - which emulation software was used for packet capture? Thanks!
Following
you have missed an important point (Routing), therefore the traffic won't be forwarded unless a static route or dynamic routing protocol is configured on both Routes so that the Routers will now where to send the traffic.
@@MrAlazawi if we don't have a route , how can the ping work ?
@@mehdifar995 and also missing access list
@@mehdifar995 ping worked because Keith pinged an IP Adresse which belongs to a connected network 10.12.12.0/24
for connected networks we don't need neither static route nor dynamic routing protocol for the Router to know where to send the packet to.
Regards
We call it "GRE over IPSEC" or "IPSEC over GRE" ?
Your face tracking is neat but extremely distracting. Thank for the great content in the CBT Nuggets CCNA Course im currently taking
Noted! Will be correcting that. Thank you Josh Kindy!
Hey Keith, I am subscribed for all your courses but I am not getting alerts. hmm weird
Thank you G. BadrichIndian
I will check my settings, thank you for the heads up, and welcome.
Will it work in cisco asa firewalls
Thank you for the question @qudratullahludin. ASA firewalls, as well as the older PIX firewalls both have the ability to implement IPsec VPN tunnels.
Will be protected!
Thank you RITUALAOS! More videos to come, including pointing out some routing challenges. Get subscribed and stay tuned for more.
Yes the traffic is encrypted/protected from PC1 to PC2.
Thank you ROHID AHAMAD! More videos to come, including details on how routing is required to get this working. Stay tuned.
Hey Keith, what is the diference between this and a VPN? This seems easier, but is it the same? Can i use this in the real world? How?
Thank you for the question Rene Gonzalez. This is one of several ways to implement an IPsec VPN tunnel. The fancy name for it is a Virtual Tunnel Interface (VTI). More VPN videos coming. Get subscribed, and stay tuned for more.
thanks a lot @@KeithBarker i´m a huge fan, i´ve been learning from you for over a decade. Thanks for the reply.
Is there a reason this is different for IPSEC than the video from 11yrs ago did something change, that makes Keith's older video not relevant?
need to get into the configuration more, not very in depth on this one
Keith, I challenge you to create a IPSec protected tunnel between a Cisco ISR and a Meraki MX.
Thank you David. I may not be that brave.
@@KeithBarker You chose wisely
I’m here
Thank you Dennis Reyes! Welcome.
Thank you very much for your explanation, the colours used makes it really easy to visualise and undertsand the concept. Love your videos too! Just wanted to add on for those who are wondering for the ipsec profile configuration, I found this video that might help: th-cam.com/video/xZrzcJxla4o/w-d-xo.htmlfeature=shared
Thank you @riwz1603!
Thanks again.
My pleasure!