Cisco router IPSec site2site configuration task list

OK...I really need this. I can't memorize all of the router cli tasks, altough they are logical and follow the basic concept of Cisco IPSec site2site technology. Anyway, just in case...
  • define transform-set
  • define isakmp policy
  • crypto ACL
  • crypto MAP
  •  assign MAP to INTF
  • define INTF ACL
  • some kind of routing must exist...static or dynamic
If everything went OK, then check established IPSec tunnel parameters with show crypto isakmp sa and show crypto ipsec sa.


Popular posts from this blog

NSX ALB LetsEncrypt with DNS-01 challenge - BIND example

VMware SD WAN - multiple locations - LAN IP address space overlapping with NAT

NSX-T Layer 2 bridging - scenarios & use cases