GRE & IPsec Tunneling

CCNP ENCOR 350-401 v1.2 EVE-NG / GNS3

مقصدObjectiveObjective

اس لیب میں آپ GRE ٹنل بنانا اور اسے IPsec سے محفوظ کرنا سیکھیں گے — site-to-site VPN کی بنیاد۔Is lab mein aap GRE tunnel banana aur usay IPsec se secure karna seekhenge — site-to-site VPN ki bunyaad.In this lab you will learn to build a GRE tunnel and secure it with IPsec — the foundation of a site-to-site VPN.

آسان مثالSimple AnalogySimple Analogy

دو دفاتر کے درمیان انٹرنیٹ ہے — جیسے دو شہروں کے درمیان سمندر۔ GRE ٹنل کا مطلب سمندر کے نیچے ایک پائپ ڈال دینا: اندر سے جو گزرے وہ محفوظ، باہر سے کوئی دیکھ نہیں سکتا۔ IPsec اس پائپ کو تالا لگا دیتا ہے — encryption۔ دونوں مل کر site-to-site VPN بنتا ہے۔Do offices ke darmiyan internet hai — jaise do shehron ke darmiyan samandar. GRE tunnel ka matlab samandar ke neeche ek pipe daal dena: andar se jo guzre wo mehfooz, bahar se koi dekh nahi sakta. IPsec us pipe ko taala laga deta hai — encryption. Dono mil kar site-to-site VPN banta hai.The internet lies between two offices — like an ocean between two cities. A GRE tunnel means laying a pipe under the ocean: whatever passes inside is safe, no one outside can see it. IPsec puts a lock on that pipe — encryption. Together they form a site-to-site VPN.

سیٹ اپLab SetupLab Setup

R1 اور R2 انٹرنیٹ (203.0.113.0/24) سے connected ہیں۔ دونوں کے پیچھے LANs ہیں۔ ڈیوائسز: 2x روٹر 2911 (R1, R2)، 2x پی سی۔ PC1: 192.168.10.10/24 (R1 کے پیچھے)۔ PC2: 192.168.30.10/24 (R2 کے پیچھے)۔R1 aur R2 internet (203.0.113.0/24) se connected. Dono ke peeche LANs hain. Devices: 2x Router 2911 (R1, R2), 2x PC PC1: 192.168.10.10/24 (R1 ke peeche). PC2: 192.168.30.10/24 (R2 ke peeche).R1 and R2 are connected to the internet (203.0.113.0/24). Both have LANs behind them. Devices: 2x Router 2911 (R1, R2), 2x PC. PC1: 192.168.10.10/24 (behind R1). PC2: 192.168.30.10/24 (behind R2).

اقداماتStepsSteps

Step 1

R1 پر GRE ٹنل۔ ٹنل انٹرفیس بنائیں، اسے IP دیں، پھر بتائیں کہ ٹنل کہاں سے نکلے (source) اور کہاں جائے (destination)۔R1 par GRE tunnel. Tunnel interface banao, usay IP do, phir batao ke tunnel kahan se nikle (source) aur kahan jaye (destination).GRE tunnel on R1. Create the tunnel interface, give it an IP, then tell it where the tunnel starts (source) and where it goes (destination).

enable
configure terminal
interface tunnel 0
ip address 10.0.0.1 255.255.255.252
tunnel source s0/0/0
tunnel destination 203.0.113.2
exit

Step 2

پھر دوسری سائٹ کا روٹ ٹنل کے ذریعے دیں۔Phir doosri site ka route tunnel ke through doThen route the other site's network through the tunnel.

ip route 192.168.30.0 255.255.255.0 10.0.0.2

Step 3

R1 پر IPsec (ٹنل کی حفاظت)۔ پہلے ISAKMP پالیسی (Phase 1): encryption، hash، pre-shared key۔R1 par IPsec (tunnel ki hifazat). Pehle ISAKMP policy (Phase 1): encryption, hash, pre-shared key.IPsec on R1 (protecting the tunnel). First the ISAKMP policy (Phase 1): encryption, hash, pre-shared key.

crypto isakmp policy 10
encryption aes
hash sha
authentication pre-share
group 2
exit
crypto isakmp key MYSECRET address 203.0.113.2

Step 4

پھر transform-set (Phase 2): اصل encryption۔ پھر crypto map میں سب جوڑیں اور باہر والے انٹرفیس پر لگائیں۔Phir transform-set (Phase 2): asal encryption. Phir crypto map mein sab joro aur bahar wale interface par lagaoThen the transform-set (Phase 2): the actual encryption. Then join everything in a crypto map and apply it on the outside interface.

crypto ipsec transform-set MYSET esp-aes esp-sha-hmac
exit
crypto map MYMAP 10 ipsec-isakmp
set peer 203.0.113.2
set transform-set MYSET
match address 100
exit
access-list 100 permit gre host 203.0.113.1 host 203.0.113.2
interface s0/0/0
crypto map MYMAP
exit

Step 5

ٹیسٹنگ: PC1 سے PC2 پنگ کریں۔Testing: PC1 se PC2 ping karo.Testing: ping PC2 from PC1.

Step 6

پھر show crypto ipsec sa سے دیکھیں کہ پیکٹس encrypt ہو رہے ہیں (encaps/decaps counters بڑھ رہے ہوں)۔Phir show crypto ipsec sa se dekho ke packets encrypt ho rahe hain (encaps/decaps counters barh rahe hon).Then check with show crypto ipsec sa that packets are being encrypted (the encaps/decaps counters should be increasing).

تصدیقVerifyVerify

show crypto isakmp sa اور show crypto ipsec sa سے ٹنل کی حالت دیکھیں۔show crypto isakmp sa aur show crypto ipsec sa se tunnel ki haalat dekho.Check the tunnel's state with show crypto isakmp sa and show crypto ipsec sa.

show crypto isakmp sa
show crypto ipsec sa

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ IPsec Phase 1 نہیں بن رہی۔IPsec Phase 1 nahi ban rahi.IPsec Phase 1 is not coming up.

✅ Pre-shared key اور ISAKMP پالیسی دونوں طرف ایک جیسی ہونی چاہیے۔ ایک حرف کا فرق بھی Phase 1 فیل کر دے گا۔Pre-shared key aur ISAKMP policy dono taraf same honi chahiye. Ek harf ka farq bhi Phase 1 fail kar dega.The pre-shared key and ISAKMP policy must match on both sides. Even a one-character difference will fail Phase 1.

⚠️ ٹنل up ہے لیکن encryption نہیں ہو رہی۔Tunnel up hai lekin encryption nahi ho rahi.The tunnel is up but no encryption is happening.

✅ Crypto map باہر والے (internet facing) انٹرفیس پر لگتا ہے، ٹنل پر نہیں۔Crypto map bahar wale (internet facing) interface par lagta hai, tunnel par nahi.The crypto map goes on the outside (internet-facing) interface, not on the tunnel.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ GRE اور IPsec میں فرق؟GRE aur IPsec mein farq?What is the difference between GRE and IPsec?

GRE ٹنل بناتا ہے لیکن encryption نہیں کرتا۔ IPsec encryption کرتا ہے لیکن ٹنل نہیں بناتا (transport mode)۔ دونوں مل کر secure ٹنل بنتا ہے۔GRE tunnel banata hai lekin encryption nahi karta. IPsec encryption karta hai lekin tunnel nahi banata (transport mode). Dono mil kar secure tunnel banta hai.GRE creates a tunnel but does not encrypt. IPsec encrypts but does not create a tunnel (transport mode). Together they make a secure tunnel.