Cisco IOS IKEv1 IPsec crypto map example (legacy)
More actions
Legacy Cisco IOS/IOS XE IKEv1 site-to-site IPsec example using a static crypto map.
Example topology
This example uses documentation-only addresses:
- Local protected network:
192.0.2.0/24 - Remote protected network:
198.51.100.0/24 - Remote VPN peer:
203.0.113.2
Replace all addresses, interfaces and secrets with values appropriate to the environment.
IKEv1 policy
Cisco's current migration guidance demonstrates AES, SHA-256 and DH group 14 for an IKEv1 crypto-map example.
crypto isakmp policy 10 encryption aes 256 hash sha256 authentication pre-share group 14 ! crypto isakmp key REPLACE_WITH_STRONG_PSK address 203.0.113.2
IPsec transform set
crypto ipsec transform-set TSET esp-aes 256 esp-sha256-hmac mode tunnel
Interesting traffic
ip access-list extended VPN-TRAFFIC permit ip 192.0.2.0 0.0.0.255 198.51.100.0 0.0.0.255
Static crypto map
crypto map CMAP 10 ipsec-isakmp set peer 203.0.113.2 set transform-set TSET set pfs group14 match address VPN-TRAFFIC
Apply the crypto map to the appropriate external interface only after validating addressing, routing, NAT behaviour and peer settings.
interface GigabitEthernet0/0 crypto map CMAP
Verify
show crypto isakmp sa show crypto ipsec sa show crypto session
Validate packet counters in both directions and confirm that the negotiated algorithms match the approved design.
Migrating away from crypto maps
Cisco documents migration from policy-based crypto maps to IPsec Virtual Tunnel Interfaces (VTIs). A VTI can simplify routing integration and decouple the routed interface from a traditional crypto-map ACL model.
See Cisco IOS IPsec VTI setup and troubleshooting before planning a migration.