Create an IPsec VPN tunnel using Packet Tracer - CCNA Security
ฝัง
- เผยแพร่เมื่อ 9 ก.พ. 2025
- danscourses.com - Learn how to create an IPsec VPN tunnel on Cisco routers using the Cisco IOS CLI. CCNA security topic.
1. Starting configurations for R1, ISP, and R3. Paste to global config mode :
hostname R1
interface g0/1
ip address 192.168.1.1 255.255.255.0
no shut
interface g0/0
ip address 209.165.100.1 255.255.255.0
no shut
exit
ip route 0.0.0.0 0.0.0.0 209.165.100.2
hostname ISP
interface g0/1
ip address 209.165.200.2 255.255.255.0
no shut
interface g0/0
ip address 209.165.100.2 255.255.255.0
no shut
exit
hostname R3
interface g0/1
ip address 192.168.3.1 255.255.255.0
no shut
interface g0/0
ip address 209.165.200.1 255.255.255.0
no shut
exit
ip route 0.0.0.0 0.0.0.0 209.165.200.2
2. Make sure routers have the security license enabled:
license boot module c1900 technology-package securityk9
3. Configure IPsec on the routers at each end of the tunnel (R1 and R3)
!R1
crypto isakmp policy 10
encryption aes 256
authentication pre-share
group 5
!
crypto isakmp key secretkey address 209.165.200.1
!
crypto ipsec transform-set R1-R3 esp-aes 256 esp-sha-hmac
!
crypto map IPSEC-MAP 10 ipsec-isakmp
set peer 209.165.200.1
set pfs group5
set security-association lifetime seconds 86400
set transform-set R1-R3
match address 100
!
interface GigabitEthernet0/0
crypto map IPSEC-MAP
!
access-list 100 permit ip 192.168.1.0 0.0.0.255 192.168.3.0 0.0.0.255
!R3
crypto isakmp policy 10
encryption aes 256
authentication pre-share
group 5
!
crypto isakmp key secretkey address 209.165.100.1
!
crypto ipsec transform-set R3-R1 esp-aes 256 esp-sha-hmac
!
crypto map IPSEC-MAP 10 ipsec-isakmp
set peer 209.165.100.1
set pfs group5
set security-association lifetime seconds 86400
set transform-set R3-R1
match address 100
!
interface GigabitEthernet0/0
crypto map IPSEC-MAP
!
access-list 100 permit ip 192.168.3.0 0.0.0.255 192.168.1.0 0.0.0.255
no one ever has able to explain ipsec like you on TH-cam, Hats off.
Totally
nee va thalaaa
Totally agree
I admire your teaching method, Dan...I appreciate that you don't rush through your tutorials. Packet Tracer has become a kind of video game to me. Please keep up the great work. Thank you!
Thank you so much sir. You totally saved one university student from crying in the corner and can't sleep for his networking assignment!!
Which course?
@danscourses - I used your videos 14 years ago whilst doing my degree, I then used them when I was teaching, and the learners loved the simplicity of your approach and now I find myself reminding myself of how to do the odd thing which I have not done in a while - and here I am.
How you have not got more views I do not know - you should.
Amazing support from you.
Thanks
Hey I am CCNA Security and you have explained everything so clearly, thank you very much mate from Costa Rica excellent
So far, the BEST IPSec config video I have EVER seen! Congratulations! YOU ROCK.
Hello sir, your fan from indonesia here.
Thx to your videos, i passed ccna rs with 912 and now have a full time job in network engineering.
You are a life-saver instructor, make a difficult subject to be easy while keeping it practical.
Please keep making video like this, i just want you to know, your videos are life-changer, for me and for other students around the world!
I love this guy. His explanations are clear, precise and so easy to absorb. His knowledge on networking is right up there with the best!
me too, i found his way of expression is concise and very clear. that's why im following his tutorials all the time
thanks for going slowly and showing, so many people on Utube talk about the whole lot and show 16 seconds of actual config at the end.
Thank you for a great tutorial. I love how you speak slowly and clearly so a beginner like me can understand things.
Greetings from Kashmir.
This video has helped me a lot in understanding this concept. I've almost watched 10 - 15 about the same but No one has explained the configuration part, like you did.
Thanks a lot
I know the video is two years old but, I must say the information is very well put together. Thanks Dan!
This is a must to follow if you are new to networking or need to brush-up your skills. doesn't talk too much, cool, and explains things in proper order.
I don't know how your videos don't have thousands and thousands of upvotes. Your video series is amazingly good.
I love that the video was watched from almost all over the world.
Thank you Professor for sharing the knowledge.
Very well explained.
Very Good Explain my Friend. I am net engineer working ISP. I have ccna, ccnp but i never seen good explain Ipsec like you)
Dan thank you so much. Im prepping for an interview as a Network Admin at what i would consider my dream company to work for here in Atlanta. Im determined to demonstrate this ability to them will blow them away. Thank you for your patience and clear direction. I set mine in in PT and it works just as you said!! Thanks again!
How was your interview?
@@AZAMKHAN-ck5dx It went great and was offered and accepted the position! Dans training and videos gave the confidence I needed to answer tech questions!
now you are employed!
could you please tell me what questions were asked in the interview , just asking for my preparation
@@AZAMKHAN-ck5dx my esp is not showing i have followed his tutorial but not working like him
Your Just the best Cisco network Teatcher over the World
Thanks. Your configuration is 100% working and I tested on Packet Tracer 8.3
Hey bud....actually this same network is not running on my 8.2.2 version...what can i doo
YOU LITRALLY SAVED MEEEEEEEEEEE, THANKSS!!!
EDIT: YOUR VOICE IS SO RELAXING BY THE WAY
This is about the best tutorial I have seen.
Bravo.
Great Video.
Good to remember that certain items in the Crypto Policy MUST match on the other side, but not all. These are
1.Hash 2. Encryption 3. Authentication 4. Diffie-Hellman Group number
Thank you Mr. Danscourses I would love to appreciate the amount of work and time that you put into making your teaching on ipsec vpn tunnel using packet tracer. indeed almost all of your teaching in every area of cisco environment, it is very short of incredibly informative and interesting to learn it easily. Many thanks once again for making time in your busy schedule give us awesome teaching. God bless you!
Thank you very much. You would kill it doing an asmr channel Dan, your voice is as smooth as butter.
Great video and straight to the point. Following this guide gives some more insight in how IPSEC VPN tunnels work under the hood and should give you some ability to answer technical questions on the job. Thanks!
the best teacher ever by far, love you SIR
Thank you, very clear and concise description of the entire configuration!!
I am self learner .it is clear and eay to understand. keep up making such lesson.
Helped with my initial university project, thanks much from Belarus!
I was just watching a video embedded in the ENSA Cisco text about IPSec in ch 8, and I swear to god it's you; sounds EXACTLY like you
This is perfect. I was so sad when I thought CPT didn't have the functionality to lab tunnels. I had no idea you could upgrade the Security Module.
thanks for the vid, this is the one i am looking for IPsec VPN tunnel to practice the concept behind.
Thank you very much sir. You've made my day. I was looking for this video for so long time, and, now i can finish my project!
THANK YOU!!!
Oh man! You just helped me to set the tunnel up! The pc was not pining initially and it pinged after multiple attempt..
Man i havent touch Cisco VPN for a while.. Mostly we use PFSense OpenVPN. Thanks for the clear video.
Thank you very much
You are the best
this license thing was killing my study project
MAAAAANY , MANY THAKS
you are great teacher that way of teaching
Hello, just found this video, very impressed you explain things very easily. Thank you!!!!
Thank you for your video. I can finally finish my report.😃
Thanks! this was helpful had some slight trouble configuring this since I'm running NAT on my lab so I had to disabled it but still it works.
everyone has complicated it
but you nailed it
You're the best Sir thank you!😊
Thanks alot sir for sharing a really valuable information. The way you teach is awesome. Thank you sooo much sir.
Hello Dan I just want to say I LOVE YOU. Thanks for all your tutorials! More power to you Godbless!
Thank you for this nice tutorial release.....
I still need to refresh this for the second time
Excellent video. Thanks for the description. Love you
complications complicated whatever it is when Dan teaches, complex things become simple things.
A great systematic & step by step explanation.
Awesome.
Thank u very much for it.
You are great at explaining concepts.
Thanks for the video.
Mate crystal clear explanation 👍
That was a great explanation, appreciate it. simple to understand.
I would request to please post us some videos on Nating and NAT types etc and Group policies too.
Thank you danscourses
Very clear explanation. Thankyou!
i like the way you explain things👍👍
thank you so much sir, from Indonesian student
Amazing explanation man! Regards ✌
This video has helped me pass a course. Thank you!
oke
Excellent video! Question, does a GRE tunnel have to be made as well? If so, how does that play in?
Great Video Sir Dans
Like always your videos are great!!! Thanks and greetings from Costa Rica!
Thanks! Pura Vida!
16:55 when i look at my pdu details i don't see any more information after esp header, do you have any idea what might be wrong?
Straightforward and understandable. Thanks Dan
This one, is amazing explanation of IPSEC, I've never seen it before. I'd like to come back to study CISCO, but the new version is socks. Dans explain it and all detail in the old version of CISCO, I don't know if the new version we'II study that, like I said, I've stopped for long years to study CISCO. The company where I work, there's any device CISCO.
Truly outstanding and informative tutorial Sir!
Hats off bro. awesome explanation
Great, You clear my knowledge
Such an insight video. Thank you!
Wow. These explanation is magnificent!!!! Really useful!
thank you man really great video and you made it clear and easy for me again thank you, god bless you
The endpoints don't ping each other in my setup. I did exactly the same setup. Could you show some commands to verify the ipsec tunnel?
Excellent video ! Great and clear explanation
AWESOME TUTORIAL!!
thank you sir now i understand ipsec vpn
hi! thank you very much for the video! Please tell me what settings you need to make on your computer? do I need to set a default gateway for it?
This is a great lab. Thank you for sharing with us all of your knowledge. One small error in the notes pasted in you tube crypto ipsec transform-set R1-R3 esp-aes 256 esp-sha-hmac should be crypto ipsec transform-set R1>-R3 esp-aes 256 esp-sha-hmac The greater than sign is missing and stops it from working....
is this true?
You made it look so easy, thanks a lot!
Excellent video, Dan! Thank you.
its one of the best in among all TH-cam vedios.appreciate
Really cool video - I'm gonna do this project on my home lab
wow ...u made it easy dude
Your videos are very precise thumbs uppp bro
Thank you for such a very informative lecture .But After carefully done the configuring of the routers following you my LAN PCs are not pinging.I dont know why , is it because i have used packet tracer version 9?
explained it better than my teacher already
very good. Nice work. you simplified the vpn conf
@danscourses what if we have large subnets on both side at that time how do you provide acl command in range.
Is there a way to permit individual networks.Please help me!
with regards,
Suyog Dahal
is there a download link for the lab in your course? can't find it.
VERY COOL DAN. VERY WELL EXPLAIN -
keep up posting videos bro.... its really helpfull✌✌✌
Superb explaination
Thank you Sir, It's very useful
great video, but why you didn't configure Nat Translation
i'm wondering in that case, should we ignore Nating network going from one site to another site ?
I seem to be the only one having problems. I've followed your steps but its seems that R1 or R3 cannot encrypt the traffic. What could cause that? I've re-read all the configs but can't find the issue...
You didn't mention it in your tutorial but I had to enable isakmp for it to work. here is the command : crypto isakmp enable
That's what I was looking for thanks for the tutorial
Awesome tutorial! Thanks for making it!
Hi. Thanks for such a great tutorial.
Hi
If I want to make connection of three or more than three sites. how can it be done
hats off to you Dan
what an amazing tutorial thanks sir
Cool ، your explain was amazing bro ، thank you
Awesome video! Thank you!