Create an IPsec VPN tunnel using Packet Tracer - CCNA Security

แชร์
ฝัง
  • เผยแพร่เมื่อ 9 ก.พ. 2025
  • danscourses.com - Learn how to create an IPsec VPN tunnel on Cisco routers using the Cisco IOS CLI. CCNA security topic.
    1. Starting configurations for R1, ISP, and R3. Paste to global config mode :
    hostname R1
    interface g0/1
    ip address 192.168.1.1 255.255.255.0
    no shut
    interface g0/0
    ip address 209.165.100.1 255.255.255.0
    no shut
    exit
    ip route 0.0.0.0 0.0.0.0 209.165.100.2
    hostname ISP
    interface g0/1
    ip address 209.165.200.2 255.255.255.0
    no shut
    interface g0/0
    ip address 209.165.100.2 255.255.255.0
    no shut
    exit
    hostname R3
    interface g0/1
    ip address 192.168.3.1 255.255.255.0
    no shut
    interface g0/0
    ip address 209.165.200.1 255.255.255.0
    no shut
    exit
    ip route 0.0.0.0 0.0.0.0 209.165.200.2
    2. Make sure routers have the security license enabled:
    license boot module c1900 technology-package securityk9
    3. Configure IPsec on the routers at each end of the tunnel (R1 and R3)
    !R1
    crypto isakmp policy 10
    encryption aes 256
    authentication pre-share
    group 5
    !
    crypto isakmp key secretkey address 209.165.200.1
    !
    crypto ipsec transform-set R1-R3 esp-aes 256 esp-sha-hmac
    !
    crypto map IPSEC-MAP 10 ipsec-isakmp
    set peer 209.165.200.1
    set pfs group5
    set security-association lifetime seconds 86400
    set transform-set R1-R3
    match address 100
    !
    interface GigabitEthernet0/0
    crypto map IPSEC-MAP
    !
    access-list 100 permit ip 192.168.1.0 0.0.0.255 192.168.3.0 0.0.0.255
    !R3
    crypto isakmp policy 10
    encryption aes 256
    authentication pre-share
    group 5
    !
    crypto isakmp key secretkey address 209.165.100.1
    !
    crypto ipsec transform-set R3-R1 esp-aes 256 esp-sha-hmac
    !
    crypto map IPSEC-MAP 10 ipsec-isakmp
    set peer 209.165.100.1
    set pfs group5
    set security-association lifetime seconds 86400
    set transform-set R3-R1
    match address 100
    !
    interface GigabitEthernet0/0
    crypto map IPSEC-MAP
    !
    access-list 100 permit ip 192.168.3.0 0.0.0.255 192.168.1.0 0.0.0.255

ความคิดเห็น • 281

  • @JaaOffendJaa
    @JaaOffendJaa 7 ปีที่แล้ว +122

    no one ever has able to explain ipsec like you on TH-cam, Hats off.

  • @dlcrdz00
    @dlcrdz00 6 ปีที่แล้ว +25

    I admire your teaching method, Dan...I appreciate that you don't rush through your tutorials. Packet Tracer has become a kind of video game to me. Please keep up the great work. Thank you!

  • @leonsaw6849
    @leonsaw6849 4 ปีที่แล้ว +5

    Thank you so much sir. You totally saved one university student from crying in the corner and can't sleep for his networking assignment!!

    • @ismt101
      @ismt101 ปีที่แล้ว

      Which course?

  • @joehurst1453
    @joehurst1453 6 หลายเดือนก่อน

    @danscourses - I used your videos 14 years ago whilst doing my degree, I then used them when I was teaching, and the learners loved the simplicity of your approach and now I find myself reminding myself of how to do the odd thing which I have not done in a while - and here I am.
    How you have not got more views I do not know - you should.
    Amazing support from you.
    Thanks

  • @jesusinirastafari
    @jesusinirastafari 6 ปีที่แล้ว +16

    Hey I am CCNA Security and you have explained everything so clearly, thank you very much mate from Costa Rica excellent

  • @JohnHenryNhammer
    @JohnHenryNhammer 5 หลายเดือนก่อน +1

    So far, the BEST IPSec config video I have EVER seen! Congratulations! YOU ROCK.

  • @MrSATYAZ
    @MrSATYAZ 6 ปีที่แล้ว +24

    Hello sir, your fan from indonesia here.
    Thx to your videos, i passed ccna rs with 912 and now have a full time job in network engineering.
    You are a life-saver instructor, make a difficult subject to be easy while keeping it practical.
    Please keep making video like this, i just want you to know, your videos are life-changer, for me and for other students around the world!

  • @scott2495
    @scott2495 5 ปีที่แล้ว +12

    I love this guy. His explanations are clear, precise and so easy to absorb. His knowledge on networking is right up there with the best!

    • @johnjunji8443
      @johnjunji8443 2 ปีที่แล้ว

      me too, i found his way of expression is concise and very clear. that's why im following his tutorials all the time

  • @dannythomas7902
    @dannythomas7902 ปีที่แล้ว

    thanks for going slowly and showing, so many people on Utube talk about the whole lot and show 16 seconds of actual config at the end.

  • @saudades416
    @saudades416 3 หลายเดือนก่อน

    Thank you for a great tutorial. I love how you speak slowly and clearly so a beginner like me can understand things.

  • @zeeshan_shaheen
    @zeeshan_shaheen 4 ปีที่แล้ว

    Greetings from Kashmir.
    This video has helped me a lot in understanding this concept. I've almost watched 10 - 15 about the same but No one has explained the configuration part, like you did.
    Thanks a lot

  • @theodorenixon7962
    @theodorenixon7962 4 ปีที่แล้ว +1

    I know the video is two years old but, I must say the information is very well put together. Thanks Dan!

  • @randymercado8466
    @randymercado8466 3 ปีที่แล้ว

    This is a must to follow if you are new to networking or need to brush-up your skills. doesn't talk too much, cool, and explains things in proper order.

  • @mrnobody6743
    @mrnobody6743 6 ปีที่แล้ว

    I don't know how your videos don't have thousands and thousands of upvotes. Your video series is amazingly good.

  • @slamtoo11
    @slamtoo11 5 ปีที่แล้ว +1

    I love that the video was watched from almost all over the world.
    Thank you Professor for sharing the knowledge.
    Very well explained.

  • @Harun1401
    @Harun1401 3 ปีที่แล้ว

    Very Good Explain my Friend. I am net engineer working ISP. I have ccna, ccnp but i never seen good explain Ipsec like you)

  • @tracysuttles
    @tracysuttles 3 ปีที่แล้ว +2

    Dan thank you so much. Im prepping for an interview as a Network Admin at what i would consider my dream company to work for here in Atlanta. Im determined to demonstrate this ability to them will blow them away. Thank you for your patience and clear direction. I set mine in in PT and it works just as you said!! Thanks again!

    • @AZAMKHAN-ck5dx
      @AZAMKHAN-ck5dx 3 ปีที่แล้ว

      How was your interview?

    • @tracysuttles
      @tracysuttles 3 ปีที่แล้ว +1

      @@AZAMKHAN-ck5dx It went great and was offered and accepted the position! Dans training and videos gave the confidence I needed to answer tech questions!

    • @AZAMKHAN-ck5dx
      @AZAMKHAN-ck5dx 3 ปีที่แล้ว

      now you are employed!
      could you please tell me what questions were asked in the interview , just asking for my preparation

    • @fahadhos
      @fahadhos 2 ปีที่แล้ว

      @@AZAMKHAN-ck5dx my esp is not showing i have followed his tutorial but not working like him

  • @majiddehbi9186
    @majiddehbi9186 17 วันที่ผ่านมา

    Your Just the best Cisco network Teatcher over the World

  • @KaranAroraItronix
    @KaranAroraItronix 3 ปีที่แล้ว +1

    Thanks. Your configuration is 100% working and I tested on Packet Tracer 8.3

    • @TYCOON-we3jp
      @TYCOON-we3jp หลายเดือนก่อน

      Hey bud....actually this same network is not running on my 8.2.2 version...what can i doo

  • @usamamasoudfadhilaldarwash707
    @usamamasoudfadhilaldarwash707 2 ปีที่แล้ว

    YOU LITRALLY SAVED MEEEEEEEEEEE, THANKSS!!!
    EDIT: YOUR VOICE IS SO RELAXING BY THE WAY

  • @igahsunday6317
    @igahsunday6317 2 ปีที่แล้ว

    This is about the best tutorial I have seen.
    Bravo.

  • @marcooconnor
    @marcooconnor 5 ปีที่แล้ว +1

    Great Video.
    Good to remember that certain items in the Crypto Policy MUST match on the other side, but not all. These are
    1.Hash 2. Encryption 3. Authentication 4. Diffie-Hellman Group number

  • @tewodroslemma6125
    @tewodroslemma6125 4 ปีที่แล้ว +1

    Thank you Mr. Danscourses I would love to appreciate the amount of work and time that you put into making your teaching on ipsec vpn tunnel using packet tracer. indeed almost all of your teaching in every area of cisco environment, it is very short of incredibly informative and interesting to learn it easily. Many thanks once again for making time in your busy schedule give us awesome teaching. God bless you!

  • @returnMarcco
    @returnMarcco 4 ปีที่แล้ว +1

    Thank you very much. You would kill it doing an asmr channel Dan, your voice is as smooth as butter.

  • @GTCG
    @GTCG 3 ปีที่แล้ว

    Great video and straight to the point. Following this guide gives some more insight in how IPSEC VPN tunnels work under the hood and should give you some ability to answer technical questions on the job. Thanks!

  • @LYESSINHO10
    @LYESSINHO10 3 ปีที่แล้ว

    the best teacher ever by far, love you SIR

  • @DwightSimmons1414
    @DwightSimmons1414 ปีที่แล้ว

    Thank you, very clear and concise description of the entire configuration!!

  • @abiyottesfay3698
    @abiyottesfay3698 6 ปีที่แล้ว

    I am self learner .it is clear and eay to understand. keep up making such lesson.

  • @Charapaha
    @Charapaha 3 ปีที่แล้ว

    Helped with my initial university project, thanks much from Belarus!

  • @scottsparling2591
    @scottsparling2591 3 ปีที่แล้ว

    I was just watching a video embedded in the ENSA Cisco text about IPSec in ch 8, and I swear to god it's you; sounds EXACTLY like you

  • @pobapecon5483
    @pobapecon5483 3 ปีที่แล้ว

    This is perfect. I was so sad when I thought CPT didn't have the functionality to lab tunnels. I had no idea you could upgrade the Security Module.

  • @johnlj_ciscocertified
    @johnlj_ciscocertified 2 ปีที่แล้ว

    thanks for the vid, this is the one i am looking for IPsec VPN tunnel to practice the concept behind.

  • @rl3d
    @rl3d 5 ปีที่แล้ว +2

    Thank you very much sir. You've made my day. I was looking for this video for so long time, and, now i can finish my project!
    THANK YOU!!!

  • @withloveforall
    @withloveforall 2 ปีที่แล้ว

    Oh man! You just helped me to set the tunnel up! The pc was not pining initially and it pinged after multiple attempt..

  • @KLNYC
    @KLNYC 5 หลายเดือนก่อน

    Man i havent touch Cisco VPN for a while.. Mostly we use PFSense OpenVPN. Thanks for the clear video.

  • @georgez.7278
    @georgez.7278 2 ปีที่แล้ว

    Thank you very much
    You are the best
    this license thing was killing my study project
    MAAAAANY , MANY THAKS

  • @cinytube9125
    @cinytube9125 3 ปีที่แล้ว

    you are great teacher that way of teaching

  • @jackherbert8771
    @jackherbert8771 4 ปีที่แล้ว

    Hello, just found this video, very impressed you explain things very easily. Thank you!!!!

  • @ilovecheese8707
    @ilovecheese8707 ปีที่แล้ว

    Thank you for your video. I can finally finish my report.😃

  • @vileyogabear3183
    @vileyogabear3183 2 ปีที่แล้ว

    Thanks! this was helpful had some slight trouble configuring this since I'm running NAT on my lab so I had to disabled it but still it works.

  • @kishoreeytham3401
    @kishoreeytham3401 4 ปีที่แล้ว

    everyone has complicated it
    but you nailed it

  • @makuei7684
    @makuei7684 3 ปีที่แล้ว +1

    You're the best Sir thank you!😊

  • @tiputechtutorials6754
    @tiputechtutorials6754 5 ปีที่แล้ว

    Thanks alot sir for sharing a really valuable information. The way you teach is awesome. Thank you sooo much sir.

  • @allenxd
    @allenxd 5 ปีที่แล้ว

    Hello Dan I just want to say I LOVE YOU. Thanks for all your tutorials! More power to you Godbless!

  • @saltech2024
    @saltech2024 4 ปีที่แล้ว

    Thank you for this nice tutorial release.....
    I still need to refresh this for the second time

  • @victoo
    @victoo ปีที่แล้ว

    Excellent video. Thanks for the description. Love you

  • @ralphsanchez5205
    @ralphsanchez5205 4 ปีที่แล้ว

    complications complicated whatever it is when Dan teaches, complex things become simple things.

  • @ns7379
    @ns7379 6 ปีที่แล้ว

    A great systematic & step by step explanation.
    Awesome.
    Thank u very much for it.

  • @priti2003
    @priti2003 6 ปีที่แล้ว

    You are great at explaining concepts.
    Thanks for the video.

  • @veerabsc
    @veerabsc 2 ปีที่แล้ว

    Mate crystal clear explanation 👍

  • @sunitaneha2422
    @sunitaneha2422 5 ปีที่แล้ว +1

    That was a great explanation, appreciate it. simple to understand.
    I would request to please post us some videos on Nating and NAT types etc and Group policies too.

  • @rajendrapanga68
    @rajendrapanga68 2 ปีที่แล้ว +1

    Thank you danscourses

  • @amilasamaraweera6209
    @amilasamaraweera6209 7 หลายเดือนก่อน

    Very clear explanation. Thankyou!

  • @besmellahhussaini4377
    @besmellahhussaini4377 2 ปีที่แล้ว

    i like the way you explain things👍👍

  • @WahyuDjuddah
    @WahyuDjuddah 3 ปีที่แล้ว

    thank you so much sir, from Indonesian student

  • @erickcalzada5026
    @erickcalzada5026 2 ปีที่แล้ว

    Amazing explanation man! Regards ✌

  • @Oplaner
    @Oplaner 4 ปีที่แล้ว

    This video has helped me pass a course. Thank you!

    • @Jaykk02
      @Jaykk02 3 ปีที่แล้ว

      oke

  • @cyrushurley2351
    @cyrushurley2351 หลายเดือนก่อน

    Excellent video! Question, does a GRE tunnel have to be made as well? If so, how does that play in?

  • @networkit1107
    @networkit1107 3 ปีที่แล้ว

    Great Video Sir Dans

  • @erebo-metal
    @erebo-metal 7 ปีที่แล้ว

    Like always your videos are great!!! Thanks and greetings from Costa Rica!

  • @DemiKrueger
    @DemiKrueger 2 ปีที่แล้ว

    16:55 when i look at my pdu details i don't see any more information after esp header, do you have any idea what might be wrong?

  • @NYCBluesTRio
    @NYCBluesTRio 4 ปีที่แล้ว

    Straightforward and understandable. Thanks Dan

  • @robersonsoliveira
    @robersonsoliveira 4 ปีที่แล้ว +2

    This one, is amazing explanation of IPSEC, I've never seen it before. I'd like to come back to study CISCO, but the new version is socks. Dans explain it and all detail in the old version of CISCO, I don't know if the new version we'II study that, like I said, I've stopped for long years to study CISCO. The company where I work, there's any device CISCO.

  • @1971bretto
    @1971bretto 4 ปีที่แล้ว

    Truly outstanding and informative tutorial Sir!

  • @simisplaytime6061
    @simisplaytime6061 2 ปีที่แล้ว

    Hats off bro. awesome explanation

  • @anilthakur5107
    @anilthakur5107 2 ปีที่แล้ว

    Great, You clear my knowledge

  • @edwardv4546
    @edwardv4546 8 หลายเดือนก่อน

    Such an insight video. Thank you!

  • @tonyli915
    @tonyli915 6 ปีที่แล้ว

    Wow. These explanation is magnificent!!!! Really useful!

  • @ahmedsayedmakhlouf3708
    @ahmedsayedmakhlouf3708 5 ปีที่แล้ว

    thank you man really great video and you made it clear and easy for me again thank you, god bless you

  • @koreandaddy_haha9550
    @koreandaddy_haha9550 ปีที่แล้ว +1

    The endpoints don't ping each other in my setup. I did exactly the same setup. Could you show some commands to verify the ipsec tunnel?

  • @NFerrari97
    @NFerrari97 4 ปีที่แล้ว

    Excellent video ! Great and clear explanation

  • @joelortiz6528
    @joelortiz6528 2 ปีที่แล้ว

    AWESOME TUTORIAL!!

  • @wibufrontend
    @wibufrontend 4 ปีที่แล้ว

    thank you sir now i understand ipsec vpn

  • @МаксимУтин-ц8д
    @МаксимУтин-ц8д ปีที่แล้ว

    hi! thank you very much for the video! Please tell me what settings you need to make on your computer? do I need to set a default gateway for it?

  • @simbadurio444
    @simbadurio444 3 ปีที่แล้ว +2

    This is a great lab. Thank you for sharing with us all of your knowledge. One small error in the notes pasted in you tube crypto ipsec transform-set R1-R3 esp-aes 256 esp-sha-hmac should be crypto ipsec transform-set R1>-R3 esp-aes 256 esp-sha-hmac The greater than sign is missing and stops it from working....

  • @alijarkas7
    @alijarkas7 4 ปีที่แล้ว

    You made it look so easy, thanks a lot!

  • @daniellima4098
    @daniellima4098 4 ปีที่แล้ว

    Excellent video, Dan! Thank you.

  • @alisony3608
    @alisony3608 6 ปีที่แล้ว

    its one of the best in among all TH-cam vedios.appreciate

  • @blorb112
    @blorb112 3 ปีที่แล้ว

    Really cool video - I'm gonna do this project on my home lab

  • @tinsonjosephbabu9888
    @tinsonjosephbabu9888 3 ปีที่แล้ว

    wow ...u made it easy dude

  • @rizwanullahmuhammad7301
    @rizwanullahmuhammad7301 6 ปีที่แล้ว

    Your videos are very precise thumbs uppp bro

  • @ignaciousnjaku2202
    @ignaciousnjaku2202 ปีที่แล้ว

    Thank you for such a very informative lecture .But After carefully done the configuring of the routers following you my LAN PCs are not pinging.I dont know why , is it because i have used packet tracer version 9?

  • @ogzsxftw
    @ogzsxftw 3 ปีที่แล้ว

    explained it better than my teacher already

  • @aniruddhamalkar4981
    @aniruddhamalkar4981 6 ปีที่แล้ว

    very good. Nice work. you simplified the vpn conf

  • @suyogdahal8185
    @suyogdahal8185 6 ปีที่แล้ว +1

    @danscourses what if we have large subnets on both side at that time how do you provide acl command in range.
    Is there a way to permit individual networks.Please help me!
    with regards,
    Suyog Dahal

  • @Fingamyaz
    @Fingamyaz 5 ปีที่แล้ว +1

    is there a download link for the lab in your course? can't find it.

  • @thuydinh7426
    @thuydinh7426 4 ปีที่แล้ว

    VERY COOL DAN. VERY WELL EXPLAIN -

  • @mohamedafkar5567
    @mohamedafkar5567 6 ปีที่แล้ว

    keep up posting videos bro.... its really helpfull✌✌✌

  • @mukunddabholkar191
    @mukunddabholkar191 4 ปีที่แล้ว

    Superb explaination

  • @Useranv
    @Useranv 3 ปีที่แล้ว

    Thank you Sir, It's very useful

  • @fezairochdi9682
    @fezairochdi9682 6 ปีที่แล้ว +1

    great video, but why you didn't configure Nat Translation
    i'm wondering in that case, should we ignore Nating network going from one site to another site ?

  • @chrislucas4406
    @chrislucas4406 5 ปีที่แล้ว +4

    I seem to be the only one having problems. I've followed your steps but its seems that R1 or R3 cannot encrypt the traffic. What could cause that? I've re-read all the configs but can't find the issue...

    • @chrislucas4406
      @chrislucas4406 5 ปีที่แล้ว +7

      You didn't mention it in your tutorial but I had to enable isakmp for it to work. here is the command : crypto isakmp enable

  • @nayboy1000
    @nayboy1000 6 ปีที่แล้ว

    That's what I was looking for thanks for the tutorial

  • @Matlesylc
    @Matlesylc 7 ปีที่แล้ว

    Awesome tutorial! Thanks for making it!

  • @christerry1156
    @christerry1156 5 ปีที่แล้ว

    Hi. Thanks for such a great tutorial.

  • @sohailmurtuza436
    @sohailmurtuza436 2 ปีที่แล้ว

    Hi
    If I want to make connection of three or more than three sites. how can it be done

  • @goranskoc4152
    @goranskoc4152 4 ปีที่แล้ว

    hats off to you Dan

  • @ahmedhosny4910
    @ahmedhosny4910 4 ปีที่แล้ว

    what an amazing tutorial thanks sir

  • @topsaad506
    @topsaad506 6 ปีที่แล้ว

    Cool ، your explain was amazing bro ، thank you

  • @samiyanes1598
    @samiyanes1598 3 ปีที่แล้ว

    Awesome video! Thank you!