Site-to-Site IPsec VPN: IKEv1/v2
CCNP ENCOR 350-401 v1.2 EVE-NG / GNS3
مقصدObjectiveObjective
اس لیب میں آپ IKEv1 اور IKEv2 کا فرق سمجھیں گے اور IKEv2 سے مکمل site-to-site IPsec VPN بنائیں گے۔ ENCOR D5 کا ٹاپک۔Is lab mein aap IKEv1 aur IKEv2 ka farq samjhenge aur IKEv2 se mukammal site-to-site IPsec VPN banayenge. ENCOR D5 ka topic.In this lab you will learn the difference between IKEv1 and IKEv2 and build a complete site-to-site IPsec VPN with IKEv2. An ENCOR D5 topic.
آسان مثالSimple AnalogySimple Analogy
IKEv1 پرانا تالا ہے — دو چابیاں (Phase 1 اور Phase 2)، 6 سے 9 پیغامات۔ IKEv2 نیا سمارٹ لاک ہے — صرف 4 پیغامات، تیز، NAT-T پہلے سے اندر، اور موبائل جیسا MOBIKE فیچر۔ دونوں کا کام ایک ہی: IPsec کے لیے محفوظ چابی کا تبادلہ۔IKEv1 purana taala hai — do chaabiyan (Phase 1 aur Phase 2), 6 se 9 paighamat. IKEv2 naya smart lock hai — sirf 4 paighamat, tez, NAT-T pehle se andar, aur mobile jaisa MOBIKE feature. Dono ka kaam ek hi: IPsec ke liye mehfooz chaabi ka tabadla.IKEv1 is an old lock — two keys (Phase 1 and Phase 2), 6 to 9 messages. IKEv2 is a new smart lock — only 4 messages, faster, NAT-T built in, and a mobile-like MOBIKE feature. Both do the same job: secure key exchange for IPsec.
سیٹ اپLab SetupLab Setup
R1 اور R2 انٹرنیٹ (203.0.113.0/24) سے connected، دونوں کے پیچھے LANs۔ ڈیوائسز: 2x روٹر 2911 (R1, R2)، 2x پی سی۔ PC1: 192.168.10.10/24 (R1 کے پیچھے)۔ PC2: 192.168.30.10/24 (R2 کے پیچھے)۔R1 aur R2 internet (203.0.113.0/24) se connected, dono ke peeche LANs. Devices: 2x Router 2911 (R1, R2), 2x PC. PC1: 192.168.10.10/24 (R1 ke peeche). PC2: 192.168.30.10/24 (R2 ke peeche).R1 and R2 connected to the internet (203.0.113.0/24), LANs behind both. Devices: 2x Router 2911 (R1, R2), 2x PC. PC1: 192.168.10.10/24 (behind R1). PC2: 192.168.30.10/24 (behind R2).
اقداماتStepsSteps
Step 1
IKEv1 بمقابلہ IKEv2: IKEv1 میں Phase 1 کے 2 modes (main/aggressive) اور 6-9 میسجز۔ IKEv2 میں صرف 4 میسجز، ایک ہی exchange، NAT-T اور EAP authentication built-in۔ نیا standard IKEv2 ہے۔IKEv1 vs IKEv2: IKEv1 mein Phase 1 ke 2 modes (main/aggressive) aur 6-9 messages. IKEv2 mein sirf 4 messages, ek hi exchange, NAT-T aur EAP authentication built-in. Naya standard IKEv2 hai.IKEv1 vs IKEv2: IKEv1 has 2 Phase 1 modes (main/aggressive) and 6-9 messages. IKEv2 has only 4 messages, a single exchange, NAT-T and EAP authentication built in. IKEv2 is the new standard.
Step 2
R1 پر IKEv2 proposal بنائیں (encryption، integrity، DH group) اور اسے policy میں ڈالیں۔ دونوں طرف یہ same ہونا چاہیے۔R1 par IKEv2 proposal banao (encryption, integrity, DH group) aur usay policy mein daalo. Dono taraf ye same hona chahiye.Create the IKEv2 proposal on R1 (encryption, integrity, DH group) and put it in a policy. It must match on both sides.
enable configure terminal crypto ikev2 proposal MY-PROPOSAL encryption aes-cbc-256 integrity sha256 group 14 exit crypto ikev2 policy MY-POLICY proposal MY-PROPOSAL exit
Step 3
Keyring میں peer کا IP اور pre-shared key بتائیں۔ Profile میں بتائیں کہ کس peer سے بات کرنی ہے اور authentication کیسے ہوگی۔Keyring mein peer ka IP aur pre-shared key batao. Profile mein batao ke kis peer se baat karni hai aur authentication kaise hogi.In the keyring, define the peer's IP and pre-shared key. In the profile, define which peer to talk to and how authentication happens.
crypto ikev2 keyring MY-KEYRING peer PEER1 address 203.0.113.2 pre-shared-key MYSECRET exit exit crypto ikev2 profile MY-PROFILE match identity remote address 203.0.113.2 255.255.255.255 authentication remote pre-share authentication local pre-share keyring local MY-KEYRING exit
Step 4
Transform-set میں اصل encryption (ESP) بتائیں اور IPsec profile بنائیں جو transform-set اور IKEv2 profile کو جوڑے۔Transform-set mein asal encryption (ESP) batao aur IPsec profile banao jo transform-set aur IKEv2 profile ko jore.Define the actual encryption (ESP) in the transform-set and create an IPsec profile that joins the transform-set and the IKEv2 profile.
crypto ipsec transform-set MY-SET esp-aes 256 esp-sha256-hmac mode tunnel exit crypto ipsec profile MY-IPSEC-PROFILE set transform-set MY-SET set ikev2-profile MY-PROFILE exit
Step 5
Tunnel انٹرفیس بنائیں اور اسے IPsec profile سے محفوظ کریں۔ tunnel protection لائن ہی ٹنل کو encrypt کرتی ہے۔Tunnel interface banao aur usay IPsec profile se mehfooz karo. tunnel protection line hi tunnel ko encrypt karti hai.Create the tunnel interface and protect it with the IPsec profile. The tunnel protection line is what encrypts the tunnel.
interface tunnel 0 ip address 10.0.0.1 255.255.255.252 tunnel source s0/0/0 tunnel destination 203.0.113.2 tunnel protection ipsec profile MY-IPSEC-PROFILE exit
Step 6
R2 پر آئینے والی کانفگ کریں (IP اور peer الٹ)۔ پھر R1 پر دوسری سائٹ کا route ٹنل کے ذریعے دیں۔R2 par aaine wali config karo (IP aur peer ulat). Phir R1 par doosri site ka route tunnel ke through do.Do the mirror config on R2 (IPs and peer reversed). Then on R1 route the other site's network through the tunnel.
ip route 192.168.30.0 255.255.255.0 10.0.0.2 exit
Step 7
ٹیسٹنگ: PC1 سے PC2 پنگ کریں۔ show crypto ikev2 sa میں SA بنی ہوئی نظر آئے، اور show crypto ipsec sa میں encaps/decaps بڑھ رہے ہوں۔Testing: PC1 se PC2 ping karo. show crypto ikev2 sa mein SA bani hui nazar aaye, aur show crypto ipsec sa mein encaps/decaps barh rahe hon.Testing: ping PC2 from PC1. The SA should appear in show crypto ikev2 sa, and encaps/decaps should be increasing in show crypto ipsec sa.
show crypto ikev2 sa show crypto ipsec sa
تصدیقVerifyVerify
show crypto ikev2 sa میں Ready state اور show crypto ipsec sa میں بڑھتے counters ہوں تو VPN کامیاب۔show crypto ikev2 sa mein Ready state aur show crypto ipsec sa mein barhte counters hon to VPN kamyab.If show crypto ikev2 sa shows Ready state and show crypto ipsec sa shows increasing counters, the VPN is a success.
show crypto ikev2 sa show crypto ipsec sa
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ IKEv2 SA نہیں بن رہی۔IKEv2 SA nahi ban rahi.The IKEv2 SA is not forming.
✅ Pre-shared key اور proposal (encryption/integrity/group) دونوں طرف same ہوں۔ match identity میں peer کا درست IP لکھیں۔Pre-shared key aur proposal (encryption/integrity/group) dono taraf same hon. match identity mein peer ka durust IP likho.The pre-shared key and proposal (encryption/integrity/group) must match on both sides. Write the peer's correct IP in match identity.
⚠️ ٹنل up ہے لیکن ٹریفک encrypt نہیں ہو رہا۔Tunnel up hai lekin traffic encrypt nahi ho raha.The tunnel is up but traffic is not being encrypted.
✅ Tunnel انٹرفیس پر tunnel protection ipsec profile لگی ہونی چاہیے۔ اس کے بغیر ٹنل plain GRE ہی رہے گا۔Tunnel interface par tunnel protection ipsec profile lagi honi chahiye. Is ke baghair tunnel plain GRE hi rahega.The tunnel interface must have tunnel protection ipsec profile. Without it, the tunnel stays plain GRE.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ IKEv1 اور IKEv2 میں بڑا فرق کیا ہے؟IKEv1 aur IKEv2 mein bara farq kya hai?What is the main difference between IKEv1 and IKEv2?
IKEv2 تیز ہے (4 میسجز بمقابلہ 6-9)، ایک ہی exchange میں کام کرتا ہے، NAT-T اور EAP built-in ہیں، اور MOBIKE سے IP بدلنے پر بھی SA قائم رہتی ہے۔IKEv2 tez hai (4 messages vs 6-9), ek hi exchange mein kaam karta hai, NAT-T aur EAP built-in hain, aur MOBIKE se IP badalne par bhi SA qaim rehti hai.IKEv2 is faster (4 messages vs 6-9), works in a single exchange, has NAT-T and EAP built in, and MOBIKE keeps the SA alive even when the IP changes.
❓ IPsec کے دو modes کون سے ہیں؟IPsec ke do modes kaun se hain?What are the two IPsec modes?
Tunnel mode (پورا پیکٹ encrypt — site-to-site میں) اور transport mode (صرف data encrypt — host-to-host میں)۔Tunnel mode (poora packet encrypt — site-to-site mein) aur transport mode (sirf data encrypt — host-to-host mein).Tunnel mode (whole packet encrypted — for site-to-site) and transport mode (only data encrypted — for host-to-host).