134
Cisco 3900 Series, Cisco 2900 Series, and Cisco 1900 Series Integrated Services Routers Generation 2 Software Configuration Guide
Chapter Configuring Security Features
Configuring VPN
The examples shown in this chapter apply only to the endpoint configuration on the Cisco 3900 series,
2900 series, and 1900 series ISRs. Any VPN connection requires both endpoints to be properly
configured in order to function. See the software configuration documentation as needed to configure
VPN for other router models.
VPN configuration information must be configured on both endpoints. You must specify parameters
such as internal IP addresses, internal subnet masks, DHCP server addresses, and Network Address
Translation (NAT).
•
“Configure a VPN over an IPSec Tunnel” section on page 134
•
“Create a Cisco Easy VPN Remote Configuration” section on page 143
•
“Configure a Site-to-Site GRE Tunnel” section on page 146
Configure a VPN over an IPSec Tunnel
Perform the following tasks to configure a VPN over an IPSec tunnel:
•
Configure the IKE Policy, page 135
•
Configure Group Policy Information, page 136
•
Apply Mode Configuration to the Crypto Map, page 138
•
Enable Policy Lookup, page 139
•
Configure IPSec Transforms and Protocols, page 140
•
Configure the IPSec Crypto Method and Parameters, page 141
•
Apply the Crypto Map to the Physical Interface, page 142
•