Site-To-Site
These scenarios show how to configure VPN site-to-site connections.
Test One P2P Tunnel
Description
Simple VPN site-to-site configuration with a single tunnel in the main VRF.
Scenario
Step 1: Set the following configuration in DUT1
:
set interfaces eth0.10 address 10.0.0.2/24 set vpn ipsec site-to-site peer SITE remote-address 10.0.0.1 set vpn ipsec auth-profile AUTH local auth pre-shared-secret test set vpn ipsec esp-group ESP-POLICY lifetime 8 MB set vpn ipsec esp-group ESP-POLICY proposal 1 encryption aes128gmac set vpn ipsec esp-group ESP-POLICY proposal 1 hash sha1 set vpn ipsec esp-group ESP-POLICY proposal 1 pfs dh-group15 set vpn ipsec ike-group IKE-POLICY dead-peer-detection interval 60 set vpn ipsec ike-group IKE-POLICY key-exchange ikev2 set vpn ipsec ike-group IKE-POLICY lifetime 28800 set vpn ipsec ike-group IKE-POLICY proposal 1 dh-group 15 set vpn ipsec ike-group IKE-POLICY proposal 1 encryption null set vpn ipsec ike-group IKE-POLICY proposal 1 hash sha1 set vpn ipsec ike-group IKE-POLICY proposal 2 dh-group 15 set vpn ipsec ike-group IKE-POLICY proposal 2 encryption aes128 set vpn ipsec ike-group IKE-POLICY proposal 2 hash sha1 set vpn ipsec site-to-site peer SITE local-address 10.0.0.2 set vpn ipsec site-to-site peer SITE tunnel 1 local prefix 10.0.0.2/32 set vpn ipsec site-to-site peer SITE tunnel 1 remote prefix 10.0.0.0/24 set vpn ipsec site-to-site peer SITE auth-profile AUTH set vpn ipsec site-to-site peer SITE connection-type respond set vpn ipsec site-to-site peer SITE ike-group IKE-POLICY set vpn ipsec site-to-site peer SITE tunnel 1 esp-group ESP-POLICY
Step 2: Set the following configuration in DUT0
:
set interfaces eth0.10 address 10.0.0.1/24 set vpn ipsec auth-profile AUTH local auth pre-shared-secret test set vpn ipsec esp-group ESP-POLICY lifetime 8 MB set vpn ipsec esp-group ESP-POLICY proposal 1 encryption aes128gmac set vpn ipsec esp-group ESP-POLICY proposal 1 hash sha1 set vpn ipsec esp-group ESP-POLICY proposal 1 pfs dh-group15 set vpn ipsec ike-group IKE-POLICY dead-peer-detection interval 60 set vpn ipsec ike-group IKE-POLICY key-exchange ikev2 set vpn ipsec ike-group IKE-POLICY lifetime 28800 set vpn ipsec ike-group IKE-POLICY proposal 1 dh-group 15 set vpn ipsec ike-group IKE-POLICY proposal 1 encryption null set vpn ipsec ike-group IKE-POLICY proposal 1 hash sha1 set vpn ipsec ike-group IKE-POLICY proposal 2 dh-group 15 set vpn ipsec ike-group IKE-POLICY proposal 2 encryption aes128 set vpn ipsec ike-group IKE-POLICY proposal 2 hash sha1 set vpn ipsec site-to-site peer SITE1 local-address 10.0.0.1 set vpn ipsec site-to-site peer SITE1 remote-address 10.0.0.2 set vpn ipsec site-to-site peer SITE1 tunnel 1 local prefix 10.0.0.1/32 set vpn ipsec site-to-site peer SITE1 tunnel 1 remote prefix 10.0.0.0/24 set vpn ipsec site-to-site peer SITE1 auth-profile AUTH set vpn ipsec site-to-site peer SITE1 connection-type initiate set vpn ipsec site-to-site peer SITE1 ike-group IKE-POLICY set vpn ipsec site-to-site peer SITE1 tunnel 1 esp-group ESP-POLICY
Step 3: Ping IP address 10.0.0.2
from DUT0
:
admin@DUT0$ ping 10.0.0.2 count 1 size 56 timeout 1Show output
PING 10.0.0.2 (10.0.0.2) 56(84) bytes of data. 64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.395 ms --- 10.0.0.2 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.395/0.395/0.395/0.000 ms
Step 4: Ping IP address 10.0.0.1
from DUT1
:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.374 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.374/0.374/0.374/0.000 ms
Step 5: Run command vpn ipsec show sa
at DUT0
and check if output matches the following regular expressions:
ESTABLISHED, IKEv2 \d+ bytes,\s+\d+ packets local\s+(\d+\.){3}[13]\/32\s+remote\s+(\d+\.){3}2\/32Show output
vpn-peer-SITE1: #1, ESTABLISHED, IKEv2, 43d2e34af30c09f0_i* 92042285dc532b60_r local '10.0.0.1' @ 10.0.0.1[500] remote '10.0.0.2' @ 10.0.0.2[500] NULL/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_3072 established 0s ago, rekeying in 20139s peer-SITE1-tunnel-1: #1, reqid 1, INSTALLED, TUNNEL, ESP:NULL_AES_GMAC-128 installed 0s ago, rekeying in 3349s, expires in 3960s in c5cd3930, 168 bytes, 2 packets, 0s ago out c512efbe, 168 bytes, 2 packets, 0s ago local 10.0.0.1/32 remote 10.0.0.2/32
Test One P2P Tunnel with VRFs
Description
Single-VRF VPN site-to-site configuration-.
Scenario
Step 1: Set the following configuration in DUT1
:
set interfaces eth0.10 address 10.0.0.2/24 set vpn ipsec site-to-site peer SITE remote-address 10.0.0.1 set vpn ipsec auth-profile AUTH local auth pre-shared-secret test set vpn ipsec esp-group ESP-POLICY lifetime 8 MB set vpn ipsec esp-group ESP-POLICY proposal 1 encryption aes128gmac set vpn ipsec esp-group ESP-POLICY proposal 1 hash sha1 set vpn ipsec esp-group ESP-POLICY proposal 1 pfs dh-group15 set vpn ipsec ike-group IKE-POLICY dead-peer-detection interval 60 set vpn ipsec ike-group IKE-POLICY key-exchange ikev2 set vpn ipsec ike-group IKE-POLICY lifetime 28800 set vpn ipsec ike-group IKE-POLICY proposal 1 dh-group 15 set vpn ipsec ike-group IKE-POLICY proposal 1 encryption null set vpn ipsec ike-group IKE-POLICY proposal 1 hash sha1 set vpn ipsec ike-group IKE-POLICY proposal 2 dh-group 15 set vpn ipsec ike-group IKE-POLICY proposal 2 encryption aes128 set vpn ipsec ike-group IKE-POLICY proposal 2 hash sha1 set vpn ipsec site-to-site peer SITE local-address 10.0.0.2 set vpn ipsec site-to-site peer SITE tunnel 1 local prefix 10.0.0.2/32 set vpn ipsec site-to-site peer SITE tunnel 1 remote prefix 10.0.0.0/24 set vpn ipsec site-to-site peer SITE auth-profile AUTH set vpn ipsec site-to-site peer SITE connection-type respond set vpn ipsec site-to-site peer SITE ike-group IKE-POLICY set vpn ipsec site-to-site peer SITE tunnel 1 esp-group ESP-POLICY
Step 2: Set the following configuration in DUT0
:
set interfaces eth0.10 address 10.0.0.1/24 set vpn ipsec auth-profile AUTH local auth pre-shared-secret test set vpn ipsec esp-group ESP-POLICY lifetime 8 MB set vpn ipsec esp-group ESP-POLICY proposal 1 encryption aes128gmac set vpn ipsec esp-group ESP-POLICY proposal 1 hash sha1 set vpn ipsec esp-group ESP-POLICY proposal 1 pfs dh-group15 set vpn ipsec ike-group IKE-POLICY dead-peer-detection interval 60 set vpn ipsec ike-group IKE-POLICY key-exchange ikev2 set vpn ipsec ike-group IKE-POLICY lifetime 28800 set vpn ipsec ike-group IKE-POLICY proposal 1 dh-group 15 set vpn ipsec ike-group IKE-POLICY proposal 1 encryption null set vpn ipsec ike-group IKE-POLICY proposal 1 hash sha1 set vpn ipsec ike-group IKE-POLICY proposal 2 dh-group 15 set vpn ipsec ike-group IKE-POLICY proposal 2 encryption aes128 set vpn ipsec ike-group IKE-POLICY proposal 2 hash sha1 set vpn ipsec site-to-site peer SITE1 local-address 10.0.0.1 set vpn ipsec site-to-site peer SITE1 remote-address 10.0.0.2 set vpn ipsec site-to-site peer SITE1 tunnel 1 local prefix 10.0.0.1/32 set vpn ipsec site-to-site peer SITE1 tunnel 1 remote prefix 10.0.0.0/24 set vpn ipsec site-to-site peer SITE1 auth-profile AUTH set vpn ipsec site-to-site peer SITE1 connection-type initiate set vpn ipsec site-to-site peer SITE1 ike-group IKE-POLICY set vpn ipsec site-to-site peer SITE1 tunnel 1 esp-group ESP-POLICY set system vrf A set interfaces eth0.10 vrf A set vpn ipsec site-to-site peer SITE1 local-vrf A set vpn ipsec site-to-site peer SITE1 tunnel 1 local-interface eth0.10
Step 3: Ping IP address 10.0.0.2
from DUT0
:
admin@DUT0$ ping 10.0.0.2 vrf A count 1 size 56 timeout 1Show output
ping: Warning: source address might be selected on device other than A. PING 10.0.0.2 (10.0.0.2) from 10.0.0.1 A: 56(84) bytes of data. 64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.405 ms --- 10.0.0.2 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.405/0.405/0.405/0.000 ms
Step 4: Ping IP address 10.0.0.1
from DUT1
:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.309 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.309/0.309/0.309/0.000 ms
Step 5: Run command vpn ipsec show sa
at DUT0
and check if output matches the following regular expressions:
ESTABLISHED, IKEv2 \d+ bytes,\s+\d+ packets local\s+(\d+\.){3}[13]\/32\s+remote\s+(\d+\.){3}2\/32Show output
vpn-peer-SITE1: #1, ESTABLISHED, IKEv2, 784e4795011cf98e_i* cb7a16128d8de1f1_r local '10.0.0.1' @ 10.0.0.1[500] remote '10.0.0.2' @ 10.0.0.2[500] NULL/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_3072 established 1s ago, rekeying in 27704s peer-SITE1-tunnel-1: #1, reqid 1, INSTALLED, TUNNEL, ESP:NULL_AES_GMAC-128 installed 1s ago, rekeying in 3494s, expires in 3959s in c2d1c99a, 168 bytes, 2 packets, 0s ago out ce449584, 168 bytes, 2 packets, 0s ago local 10.0.0.1/32 remote 10.0.0.2/32
Test Two P2P Tunnels With VRFs
Description
Multiple VPN site-to-site connections using different VRFs (no overlapped IP addresses).
Scenario
Step 1: Set the following configuration in DUT1
:
set interfaces eth0.10 address 10.0.0.2/24 set vpn ipsec site-to-site peer SITE remote-address 10.0.0.1 set vpn ipsec auth-profile AUTH local auth pre-shared-secret test set vpn ipsec esp-group ESP-POLICY lifetime 8 MB set vpn ipsec esp-group ESP-POLICY proposal 1 encryption aes128gmac set vpn ipsec esp-group ESP-POLICY proposal 1 hash sha1 set vpn ipsec esp-group ESP-POLICY proposal 1 pfs dh-group15 set vpn ipsec ike-group IKE-POLICY dead-peer-detection interval 60 set vpn ipsec ike-group IKE-POLICY key-exchange ikev2 set vpn ipsec ike-group IKE-POLICY lifetime 28800 set vpn ipsec ike-group IKE-POLICY proposal 1 dh-group 15 set vpn ipsec ike-group IKE-POLICY proposal 1 encryption null set vpn ipsec ike-group IKE-POLICY proposal 1 hash sha1 set vpn ipsec ike-group IKE-POLICY proposal 2 dh-group 15 set vpn ipsec ike-group IKE-POLICY proposal 2 encryption aes128 set vpn ipsec ike-group IKE-POLICY proposal 2 hash sha1 set vpn ipsec site-to-site peer SITE local-address 10.0.0.2 set vpn ipsec site-to-site peer SITE tunnel 1 local prefix 10.0.0.2/32 set vpn ipsec site-to-site peer SITE tunnel 1 remote prefix 10.0.0.0/24 set vpn ipsec site-to-site peer SITE auth-profile AUTH set vpn ipsec site-to-site peer SITE connection-type respond set vpn ipsec site-to-site peer SITE ike-group IKE-POLICY set vpn ipsec site-to-site peer SITE tunnel 1 esp-group ESP-POLICY
Step 2: Set the following configuration in DUT2
:
set interfaces eth0.20 address 10.0.0.2/24 set vpn ipsec site-to-site peer SITE remote-address 10.0.0.3 set vpn ipsec auth-profile AUTH local auth pre-shared-secret test set vpn ipsec esp-group ESP-POLICY lifetime 8 MB set vpn ipsec esp-group ESP-POLICY proposal 1 encryption aes128gmac set vpn ipsec esp-group ESP-POLICY proposal 1 hash sha1 set vpn ipsec esp-group ESP-POLICY proposal 1 pfs dh-group15 set vpn ipsec ike-group IKE-POLICY dead-peer-detection interval 60 set vpn ipsec ike-group IKE-POLICY key-exchange ikev2 set vpn ipsec ike-group IKE-POLICY lifetime 28800 set vpn ipsec ike-group IKE-POLICY proposal 1 dh-group 15 set vpn ipsec ike-group IKE-POLICY proposal 1 encryption null set vpn ipsec ike-group IKE-POLICY proposal 1 hash sha1 set vpn ipsec ike-group IKE-POLICY proposal 2 dh-group 15 set vpn ipsec ike-group IKE-POLICY proposal 2 encryption aes128 set vpn ipsec ike-group IKE-POLICY proposal 2 hash sha1 set vpn ipsec site-to-site peer SITE local-address 10.0.0.2 set vpn ipsec site-to-site peer SITE tunnel 1 local prefix 10.0.0.2/32 set vpn ipsec site-to-site peer SITE tunnel 1 remote prefix 10.0.0.0/24 set vpn ipsec site-to-site peer SITE auth-profile AUTH set vpn ipsec site-to-site peer SITE connection-type respond set vpn ipsec site-to-site peer SITE ike-group IKE-POLICY set vpn ipsec site-to-site peer SITE tunnel 1 esp-group ESP-POLICY
Step 3: Set the following configuration in DUT0
:
set interfaces eth0.10 address 10.0.0.1/24 set vpn ipsec auth-profile AUTH local auth pre-shared-secret test set vpn ipsec esp-group ESP-POLICY lifetime 8 MB set vpn ipsec esp-group ESP-POLICY proposal 1 encryption aes128gmac set vpn ipsec esp-group ESP-POLICY proposal 1 hash sha1 set vpn ipsec esp-group ESP-POLICY proposal 1 pfs dh-group15 set vpn ipsec ike-group IKE-POLICY dead-peer-detection interval 60 set vpn ipsec ike-group IKE-POLICY key-exchange ikev2 set vpn ipsec ike-group IKE-POLICY lifetime 28800 set vpn ipsec ike-group IKE-POLICY proposal 1 dh-group 15 set vpn ipsec ike-group IKE-POLICY proposal 1 encryption null set vpn ipsec ike-group IKE-POLICY proposal 1 hash sha1 set vpn ipsec ike-group IKE-POLICY proposal 2 dh-group 15 set vpn ipsec ike-group IKE-POLICY proposal 2 encryption aes128 set vpn ipsec ike-group IKE-POLICY proposal 2 hash sha1 set vpn ipsec site-to-site peer SITE1 local-address 10.0.0.1 set vpn ipsec site-to-site peer SITE1 remote-address 10.0.0.2 set vpn ipsec site-to-site peer SITE1 tunnel 1 local prefix 10.0.0.1/32 set vpn ipsec site-to-site peer SITE1 tunnel 1 remote prefix 10.0.0.0/24 set vpn ipsec site-to-site peer SITE1 auth-profile AUTH set vpn ipsec site-to-site peer SITE1 connection-type initiate set vpn ipsec site-to-site peer SITE1 ike-group IKE-POLICY set vpn ipsec site-to-site peer SITE1 tunnel 1 esp-group ESP-POLICY set system vrf A set interfaces eth0.10 vrf A set vpn ipsec site-to-site peer SITE1 local-vrf A set vpn ipsec site-to-site peer SITE1 tunnel 1 local-interface eth0.10 set system vrf B set interfaces eth1.20 address 10.0.0.3/24 set interfaces eth1.20 vrf B set vpn ipsec site-to-site peer SITE2 local-vrf B set vpn ipsec site-to-site peer SITE2 tunnel 1 local-interface eth1.20 set vpn ipsec site-to-site peer SITE2 local-address 10.0.0.3 set vpn ipsec site-to-site peer SITE2 remote-address 10.0.0.2 set vpn ipsec site-to-site peer SITE2 tunnel 1 local prefix 10.0.0.3/32 set vpn ipsec site-to-site peer SITE2 tunnel 1 remote prefix 10.0.0.0/24 set vpn ipsec site-to-site peer SITE2 auth-profile AUTH set vpn ipsec site-to-site peer SITE2 connection-type initiate set vpn ipsec site-to-site peer SITE2 ike-group IKE-POLICY set vpn ipsec site-to-site peer SITE2 tunnel 1 esp-group ESP-POLICY
Step 4: Ping IP address 10.0.0.2
from DUT0
:
admin@DUT0$ ping 10.0.0.2 vrf A count 1 size 56 timeout 1Show output
ping: Warning: source address might be selected on device other than A. PING 10.0.0.2 (10.0.0.2) from 10.0.0.1 A: 56(84) bytes of data. 64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.330 ms --- 10.0.0.2 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.330/0.330/0.330/0.000 ms
Step 5: Ping IP address 10.0.0.1
from DUT1
:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.421 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.421/0.421/0.421/0.000 ms
Step 6: Ping IP address 10.0.0.2
from DUT0
:
admin@DUT0$ ping 10.0.0.2 vrf B count 1 size 56 timeout 1Show output
ping: Warning: source address might be selected on device other than B. PING 10.0.0.2 (10.0.0.2) from 10.0.0.3 B: 56(84) bytes of data. 64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.404 ms --- 10.0.0.2 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.404/0.404/0.404/0.000 ms
Step 7: Ping IP address 10.0.0.3
from DUT2
:
admin@DUT2$ ping 10.0.0.3 count 1 size 56 timeout 1Show output
PING 10.0.0.3 (10.0.0.3) 56(84) bytes of data. 64 bytes from 10.0.0.3: icmp_seq=1 ttl=64 time=0.315 ms --- 10.0.0.3 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.315/0.315/0.315/0.000 ms
Step 8: Run command vpn ipsec show sa
at DUT0
and check if output matches the following regular expressions:
ESTABLISHED, IKEv2 \d+ bytes,\s+\d+ packets local\s+(\d+\.){3}[13]\/32\s+remote\s+(\d+\.){3}2\/32Show output
vpn-peer-SITE1: #2, ESTABLISHED, IKEv2, 462bd69ef1f37a4c_i* 28895805ec3933eb_r local '10.0.0.1' @ 10.0.0.1[500] remote '10.0.0.2' @ 10.0.0.2[500] NULL/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_3072 established 1s ago, rekeying in 26785s peer-SITE1-tunnel-1: #2, reqid 1, INSTALLED, TUNNEL, ESP:NULL_AES_GMAC-128 installed 1s ago, rekeying in 3439s, expires in 3959s in cd9f142a, 168 bytes, 2 packets, 1s ago out cdf6bdda, 168 bytes, 2 packets, 1s ago local 10.0.0.1/32 remote 10.0.0.2/32 vpn-peer-SITE2: #1, ESTABLISHED, IKEv2, 3924baf2176bf612_i* cd8e3611a4ed8c81_r local '10.0.0.3' @ 10.0.0.3[500] remote '10.0.0.2' @ 10.0.0.2[500] NULL/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_3072 established 1s ago, rekeying in 16823s peer-SITE2-tunnel-1: #1, reqid 2, INSTALLED, TUNNEL, ESP:NULL_AES_GMAC-128 installed 1s ago, rekeying in 3314s, expires in 3959s in c3298eda, 168 bytes, 2 packets, 0s ago out cfc2f6b6, 168 bytes, 2 packets, 0s ago local 10.0.0.3/32 remote 10.0.0.2/32
Test Two P2P Tunnels With VRFs And Overlapped IP Addresses
Description
Multiple VPN site-to-site connections using different VRFs (overlapped IP addresses).
Scenario
Step 1: Set the following configuration in DUT1
:
set interfaces eth0.10 address 10.0.0.2/24 set vpn ipsec site-to-site peer SITE remote-address 10.0.0.1 set vpn ipsec auth-profile AUTH local auth pre-shared-secret test set vpn ipsec esp-group ESP-POLICY lifetime 8 MB set vpn ipsec esp-group ESP-POLICY proposal 1 encryption aes128gmac set vpn ipsec esp-group ESP-POLICY proposal 1 hash sha1 set vpn ipsec esp-group ESP-POLICY proposal 1 pfs dh-group15 set vpn ipsec ike-group IKE-POLICY dead-peer-detection interval 60 set vpn ipsec ike-group IKE-POLICY key-exchange ikev2 set vpn ipsec ike-group IKE-POLICY lifetime 28800 set vpn ipsec ike-group IKE-POLICY proposal 1 dh-group 15 set vpn ipsec ike-group IKE-POLICY proposal 1 encryption null set vpn ipsec ike-group IKE-POLICY proposal 1 hash sha1 set vpn ipsec ike-group IKE-POLICY proposal 2 dh-group 15 set vpn ipsec ike-group IKE-POLICY proposal 2 encryption aes128 set vpn ipsec ike-group IKE-POLICY proposal 2 hash sha1 set vpn ipsec site-to-site peer SITE local-address 10.0.0.2 set vpn ipsec site-to-site peer SITE tunnel 1 local prefix 10.0.0.2/32 set vpn ipsec site-to-site peer SITE tunnel 1 remote prefix 10.0.0.0/24 set vpn ipsec site-to-site peer SITE auth-profile AUTH set vpn ipsec site-to-site peer SITE connection-type respond set vpn ipsec site-to-site peer SITE ike-group IKE-POLICY set vpn ipsec site-to-site peer SITE tunnel 1 esp-group ESP-POLICY
Step 2: Set the following configuration in DUT2
:
set interfaces eth0.20 address 10.0.0.2/24 set vpn ipsec site-to-site peer SITE remote-address 10.0.0.3 set vpn ipsec auth-profile AUTH local auth pre-shared-secret test set vpn ipsec esp-group ESP-POLICY lifetime 8 MB set vpn ipsec esp-group ESP-POLICY proposal 1 encryption aes128gmac set vpn ipsec esp-group ESP-POLICY proposal 1 hash sha1 set vpn ipsec esp-group ESP-POLICY proposal 1 pfs dh-group15 set vpn ipsec ike-group IKE-POLICY dead-peer-detection interval 60 set vpn ipsec ike-group IKE-POLICY key-exchange ikev2 set vpn ipsec ike-group IKE-POLICY lifetime 28800 set vpn ipsec ike-group IKE-POLICY proposal 1 dh-group 15 set vpn ipsec ike-group IKE-POLICY proposal 1 encryption null set vpn ipsec ike-group IKE-POLICY proposal 1 hash sha1 set vpn ipsec ike-group IKE-POLICY proposal 2 dh-group 15 set vpn ipsec ike-group IKE-POLICY proposal 2 encryption aes128 set vpn ipsec ike-group IKE-POLICY proposal 2 hash sha1 set vpn ipsec site-to-site peer SITE local-address 10.0.0.2 set vpn ipsec site-to-site peer SITE tunnel 1 local prefix 10.0.0.2/32 set vpn ipsec site-to-site peer SITE tunnel 1 remote prefix 10.0.0.0/24 set vpn ipsec site-to-site peer SITE auth-profile AUTH set vpn ipsec site-to-site peer SITE connection-type respond set vpn ipsec site-to-site peer SITE ike-group IKE-POLICY set vpn ipsec site-to-site peer SITE tunnel 1 esp-group ESP-POLICY del vpn ipsec site-to-site peer SITE remote-address set vpn ipsec site-to-site peer SITE remote-address 10.0.0.1
Step 3: Set the following configuration in DUT0
:
set interfaces eth0.10 address 10.0.0.1/24 set vpn ipsec auth-profile AUTH local auth pre-shared-secret test set vpn ipsec esp-group ESP-POLICY lifetime 8 MB set vpn ipsec esp-group ESP-POLICY proposal 1 encryption aes128gmac set vpn ipsec esp-group ESP-POLICY proposal 1 hash sha1 set vpn ipsec esp-group ESP-POLICY proposal 1 pfs dh-group15 set vpn ipsec ike-group IKE-POLICY dead-peer-detection interval 60 set vpn ipsec ike-group IKE-POLICY key-exchange ikev2 set vpn ipsec ike-group IKE-POLICY lifetime 28800 set vpn ipsec ike-group IKE-POLICY proposal 1 dh-group 15 set vpn ipsec ike-group IKE-POLICY proposal 1 encryption null set vpn ipsec ike-group IKE-POLICY proposal 1 hash sha1 set vpn ipsec ike-group IKE-POLICY proposal 2 dh-group 15 set vpn ipsec ike-group IKE-POLICY proposal 2 encryption aes128 set vpn ipsec ike-group IKE-POLICY proposal 2 hash sha1 set vpn ipsec site-to-site peer SITE1 local-address 10.0.0.1 set vpn ipsec site-to-site peer SITE1 remote-address 10.0.0.2 set vpn ipsec site-to-site peer SITE1 tunnel 1 local prefix 10.0.0.1/32 set vpn ipsec site-to-site peer SITE1 tunnel 1 remote prefix 10.0.0.0/24 set vpn ipsec site-to-site peer SITE1 auth-profile AUTH set vpn ipsec site-to-site peer SITE1 connection-type initiate set vpn ipsec site-to-site peer SITE1 ike-group IKE-POLICY set vpn ipsec site-to-site peer SITE1 tunnel 1 esp-group ESP-POLICY set system vrf A set interfaces eth0.10 vrf A set vpn ipsec site-to-site peer SITE1 local-vrf A set vpn ipsec site-to-site peer SITE1 tunnel 1 local-interface eth0.10 set system vrf B set interfaces eth1.20 address 10.0.0.3/24 set interfaces eth1.20 vrf B set vpn ipsec site-to-site peer SITE2 local-vrf B set vpn ipsec site-to-site peer SITE2 tunnel 1 local-interface eth1.20 del interfaces eth1.20 address set interfaces eth1.20 address 10.0.0.1/24 set vpn ipsec site-to-site peer SITE2 local-address 10.0.0.1 set vpn ipsec site-to-site peer SITE2 remote-address 10.0.0.2 set vpn ipsec site-to-site peer SITE2 tunnel 1 local prefix 10.0.0.1/32 set vpn ipsec site-to-site peer SITE2 tunnel 1 remote prefix 10.0.0.0/24 set vpn ipsec site-to-site peer SITE2 auth-profile AUTH set vpn ipsec site-to-site peer SITE2 connection-type initiate set vpn ipsec site-to-site peer SITE2 ike-group IKE-POLICY set vpn ipsec site-to-site peer SITE2 tunnel 1 esp-group ESP-POLICY
Step 4: Ping IP address 10.0.0.2
from DUT0
:
admin@DUT0$ ping 10.0.0.2 vrf A count 1 size 56 timeout 1Show output
ping: Warning: source address might be selected on device other than A. PING 10.0.0.2 (10.0.0.2) from 10.0.0.1 A: 56(84) bytes of data. 64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.392 ms --- 10.0.0.2 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.392/0.392/0.392/0.000 ms
Step 5: Ping IP address 10.0.0.1
from DUT1
:
admin@DUT1$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.413 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.413/0.413/0.413/0.000 ms
Step 6: Ping IP address 10.0.0.2
from DUT0
:
admin@DUT0$ ping 10.0.0.2 vrf B count 1 size 56 timeout 1Show output
ping: Warning: source address might be selected on device other than B. PING 10.0.0.2 (10.0.0.2) from 10.0.0.1 B: 56(84) bytes of data. 64 bytes from 10.0.0.2: icmp_seq=1 ttl=64 time=0.357 ms --- 10.0.0.2 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.357/0.357/0.357/0.000 ms
Step 7: Ping IP address 10.0.0.1
from DUT2
:
admin@DUT2$ ping 10.0.0.1 count 1 size 56 timeout 1Show output
PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data. 64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.350 ms --- 10.0.0.1 ping statistics --- 1 packets transmitted, 1 received, 0% packet loss, time 0ms rtt min/avg/max/mdev = 0.350/0.350/0.350/0.000 ms
Step 8: Run command vpn ipsec show sa
at DUT0
and check if output matches the following regular expressions:
ESTABLISHED, IKEv2 \d+ bytes,\s+\d+ packets local\s+(\d+\.){3}[13]\/32\s+remote\s+(\d+\.){3}2\/32Show output
vpn-peer-SITE1: #2, ESTABLISHED, IKEv2, 5b735ab6013f04a2_i* 35ccd69c5015e7da_r local '10.0.0.1' @ 10.0.0.1[500] remote '10.0.0.2' @ 10.0.0.2[500] NULL/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_3072 established 1s ago, rekeying in 27546s peer-SITE1-tunnel-1: #2, reqid 1, INSTALLED, TUNNEL, ESP:NULL_AES_GMAC-128 installed 1s ago, rekeying in 3250s, expires in 3959s in c775106f, 168 bytes, 2 packets, 1s ago out c3f128f4, 168 bytes, 2 packets, 1s ago local 10.0.0.1/32 remote 10.0.0.2/32 vpn-peer-SITE2: #1, ESTABLISHED, IKEv2, e818397d15e90817_i* fce1bbfa21977e9b_r local '10.0.0.1' @ 10.0.0.1[500] remote '10.0.0.2' @ 10.0.0.2[500] NULL/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_3072 established 1s ago, rekeying in 16677s peer-SITE2-tunnel-1: #1, reqid 1, INSTALLED, TUNNEL, ESP:NULL_AES_GMAC-128 installed 1s ago, rekeying in 3492s, expires in 3959s in c0c38984, 168 bytes, 2 packets, 1s ago out c47c783f, 168 bytes, 2 packets, 1s ago local 10.0.0.1/32 remote 10.0.0.2/32