


Explore why virtual private networks use IPsec to create secure tunnels over shared networks, comparing AH and ESP: origin authentication, encryption, integrity, and tunnel versus transport modes.
Begin configuring a vpn by creating ike phase 1 policies and crypto acl, using pre-shared keys, 3des, sha, dh group 5, and a 24-hour lifetime.
Continue configuring IKE phase 1 policy on router 3, verify hash, encryption, and DH group matches, set lifetime with IOS help, and note the recipient uses the lower value.
Configure IKE phase 2 by creating pre-shared keys and transform sets with encryption and authentication, then set lifetime and idle time in seconds or kilobytes and generate traffic.
Learn how crypto ACLs drive VPN builds in IPsec, defining outbound and inbound interesting traffic with extended ACLs, and why careful mirror configurations and avoiding permit any are essential.
Learn to configure a crypto map on a router, turning an ACL into a crypto ACL, set a peer and a transform set, and apply the map to the interface.
Watch your site-to-site vpn come to life by running debug crypto ipsec, sending traffic, and verifying ipsec sa, crypto map, and quick mode status.
Don't know what AH and ESP are? No problem! Join up right now and you will -- and you'll be notified of every new video I post to this course until its completion in about 10 days.
Thanks for making TBA and Udemy part of your exam success!
Chris Bryant
CCIE #12933
"The Computer Certification Bulldog"