Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

Cisco IOS IKEv1 IPsec crypto map example (legacy)

From Tech-Wiki
(Redirected from VPN using crypto map)


Legacy Cisco IOS/IOS XE IKEv1 site-to-site IPsec example using a static crypto map.

!
Legacy IKEv1 configuration
This article is retained for maintaining and troubleshooting existing IKEv1 crypto-map deployments. For new VPN designs, evaluate the current Cisco IKEv2 and VTI guidance supported by the target platform and peer rather than copying a legacy design unchanged.
ⓘ
Validation status
Reviewed against current Cisco IOS XE IPsec guidance and Cisco's current crypto-map-to-VTI migration guidance on 27 September 2026. The original Tech-Wiki example used 3DES, MD5 and Diffie-Hellman group 2; Cisco no longer recommends those algorithms.

Example topology

This example uses documentation-only addresses:

  • Local protected network: 192.0.2.0/24
  • Remote protected network: 198.51.100.0/24
  • Remote VPN peer: 203.0.113.2

Replace all addresses, interfaces and secrets with values appropriate to the environment.

IKEv1 policy

Cisco's current migration guidance demonstrates AES, SHA-256 and DH group 14 for an IKEv1 crypto-map example.

>_IKEv1 policy and peer key
crypto isakmp policy 10
 encryption aes 256
 hash sha256
 authentication pre-share
 group 14
!
crypto isakmp key REPLACE_WITH_STRONG_PSK address 203.0.113.2
!
Protect pre-shared keys
Use an organisation-approved secret-management process and the strongest supported secure-storage mechanism on the device. Do not place production pre-shared keys in documentation, tickets or source repositories.

IPsec transform set

>_Define the IPsec transform set
crypto ipsec transform-set TSET esp-aes 256 esp-sha256-hmac
 mode tunnel

Interesting traffic

>_Define protected traffic
ip access-list extended VPN-TRAFFIC
 permit ip 192.0.2.0 0.0.0.255 198.51.100.0 0.0.0.255

Static crypto map

>_Create the crypto map
crypto map CMAP 10 ipsec-isakmp
 set peer 203.0.113.2
 set transform-set TSET
 set pfs group14
 match address VPN-TRAFFIC

Apply the crypto map to the appropriate external interface only after validating addressing, routing, NAT behaviour and peer settings.

>_Apply the crypto map
interface GigabitEthernet0/0
 crypto map CMAP

Verify

>_IKEv1 and IPsec status
show crypto isakmp sa
show crypto ipsec sa
show crypto session

Validate packet counters in both directions and confirm that the negotiated algorithms match the approved design.

Migrating away from crypto maps

Cisco documents migration from policy-based crypto maps to IPsec Virtual Tunnel Interfaces (VTIs). A VTI can simplify routing integration and decouple the routed interface from a traditional crypto-map ACL model.

See Cisco IOS IPsec VTI setup and troubleshooting before planning a migration.

Official references

See also