<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT certification lab simulation &#187; cisco exam</title>
	<atom:link href="http://www.netemu.net/tag/cisco-exam/feed" rel="self" type="application/rss+xml" />
	<link>http://www.netemu.net</link>
	<description>Share IT technologies and lab experiences with you</description>
	<lastBuildDate>Fri, 10 Apr 2009 01:38:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>dynamips lab:Cisco L2TP over IPSec With windows client</title>
		<link>http://www.netemu.net/dynamips/dynamips-labcisco-l2tp-over-ipsec-with-windows-client/85.html</link>
		<comments>http://www.netemu.net/dynamips/dynamips-labcisco-l2tp-over-ipsec-with-windows-client/85.html#comments</comments>
		<pubDate>Fri, 10 Apr 2009 01:38:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[dynamips]]></category>
		<category><![CDATA[dynamips lab]]></category>
		<category><![CDATA[cisco certification]]></category>
		<category><![CDATA[cisco exam]]></category>
		<category><![CDATA[cisco simulator]]></category>
		<category><![CDATA[dynagen]]></category>
		<category><![CDATA[ipsec]]></category>

		<guid isPermaLink="false">http://www.ciscosim.net/dynamips/dynamips-labcisco-l2tp-over-ipsec-with-windows-client/82/</guid>
		<description><![CDATA[Cisco L2TP over IPSec With Windows ClientI have completed this lab on Dynamips 7200 simulator, the topology is as follow: 1. L2TP Over IPSec Server Configuration (R1) R1#sh run version 12.4 ! hostname R1 ! vpdn enable ! vpdn-group 1 ! Default L2TP VPDN group accept-dialin protocol l2tp virtual-template 1 no l2tp tunnel authentication ! [...]]]></description>
			<content:encoded><![CDATA[<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Cisco L2TP over IPSec With Windows ClientI have completed this lab on Dynamips 7200 simulator, the topology is as follow:</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><img src="http://lh3.ggpht.com/_KFnl8FWE-Rw/Sd6jD0dVZWI/AAAAAAAAAPE/yr1ZNtwgg_g/Cisco%20L2TP%20over%20IPSec%20With%20Windows%20Client.jpg?imgmax=512" alt="Cisco L2TP over IPSec With Windows Client.jpg" height="79" width="450"/></p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">
<p> <span id="more-85"></span>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">1. L2TP Over IPSec Server Configuration (R1)</p>
<table cellpadding="0" cellspacing="0" style="mso-cellspacing: 0cm; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 0cm 0cm 0cm" border="1">
<tbody>
<tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes; mso-yfti-lastrow: yes">
<td width="568" style="BORDER-RIGHT: #ece9d8; PADDING-RIGHT: 0cm; BORDER-TOP: #ece9d8; PADDING-LEFT: 0cm; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 426pt; PADDING-TOP: 0cm; BORDER-BOTTOM: #ece9d8; BACKGROUND-COLOR: transparent" valign="top">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan">R1#sh run <br />version 12.4 <br />! <br />hostname R1 <br />! <br />vpdn enable <br />! <br />vpdn-group 1 <br />! Default L2TP VPDN group <br />accept-dialin <br />protocol l2tp <br />virtual-template 1 <br />no l2tp tunnel authentication <br />! <br />username stve6307 password 0 cisco <br />! <br />crypto isakmp policy 10 <br />encr 3des <br />authentication pre-share <br />group 2 <br />crypto isakmp key cisco1234 address 0.0.0.0 0.0.0.0 <br />! <br />crypto ipsec transform-set ccsp esp-3des esp-sha-hmac <br />mode transport <br />! <br />crypto dynamic-map cc 10 <br />set nat demux <br />set transform-set ccsp <br />! <br />crypto map cisco 10 ipsec-isakmp dynamic cc <br />! <br />interface Loopback0 <br />ip address 10.1.1.1 255.255.255.0 <br />! <br />interface Serial1/2 <br />ip address 11.1.1.1 255.255.255.252 <br />serial restart-delay 0 <br />crypto map cisco <br />! <br />interface Virtual-Template1 <br />ip unnumbered Loopback0 <br />peer default ip address pool l2tp-pool <br />ppp authentication chap <br />! <br />ip local pool l2tp-pool 192.168.1.1 192.168.1.100 <br />! <br />ip route 0.0.0.0 0.0.0.0 11.1.1.2</p>
</td>
</tr>
</tbody>
</table>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">2. Windows Configuration</p>
<table cellpadding="0" cellspacing="0" style="mso-cellspacing: 0cm; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 0cm 0cm 0cm" border="1">
<tbody>
<tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes; mso-yfti-lastrow: yes">
<td width="568" style="BORDER-RIGHT: #ece9d8; PADDING-RIGHT: 0cm; BORDER-TOP: #ece9d8; PADDING-LEFT: 0cm; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 426pt; PADDING-TOP: 0cm; BORDER-BOTTOM: #ece9d8; BACKGROUND-COLOR: transparent" valign="top">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan">1. Import the register as follow: <br />&#8212;&#8212;&#8212; <br />REGEDIT4 [HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Rasman\Parameters] <br />&#8220;ProhibitIpSec&#8221;=dword:00000001 <br />&#8212;&#8212;&#8212; <br />2. Use gpedit.msc to configure &#8220;IP security policy&#8221;, please refer to Microsoft.com. <br />3. Setup a dialer interface and dial to the server.</p>
</td>
</tr>
</tbody>
</table>
<p style="MARGIN: 0cm 0cm 0pt">
<p xmlns="" class="zoundry_raven_tags">  <!-- Tag links generated by Zoundry Raven. Do not manually edit. http://www.zoundryraven.com -->  <span class="ztags"><span class="ztagspace">Flickr</span> : <a href="http://www.flickr.com/photos/tags/cisco%20certification" class="ztag" rel="tag">cisco certification</a>, <a href="http://www.flickr.com/photos/tags/cisco%20exam" class="ztag" rel="tag">cisco exam</a>, <a href="http://www.flickr.com/photos/tags/cisco%20simulator" class="ztag" rel="tag">cisco simulator</a>, <a href="http://www.flickr.com/photos/tags/dynagen" class="ztag" rel="tag">dynagen</a>, <a href="http://www.flickr.com/photos/tags/dynamips" class="ztag" rel="tag">dynamips</a>, <a href="http://www.flickr.com/photos/tags/ipsec" class="ztag" rel="tag">ipsec</a></span> </p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ipsec-easyvpn-dmvpn-on-dynamips/84.html" title="dynamips lab:Cisco IPSec EasyVPN &amp; DMVPN on dynamips">dynamips lab:Cisco IPSec EasyVPN &amp; DMVPN on dynamips</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-ssl-vpn-on-dynamips-test-note2/83.html" title="dynamips lab:Cisco ios ssl vpn on dynamips test note2">dynamips lab:Cisco ios ssl vpn on dynamips test note2</a> (2)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labccnp-lab-for-dynamips/68.html" title="dynamips lab:ccnp lab for dynamips">dynamips lab:ccnp lab for dynamips</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labccie-topo/66.html" title="dynamips lab:CCIE topo">dynamips lab:CCIE topo</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-ssl-vpn-on-dynamips-test-note/76.html" title="dynamips lab:Cisco IOS SSL VPN on dynamips test note">dynamips lab:Cisco IOS SSL VPN on dynamips test note</a> (2)</li><li><a href="http://www.netemu.net/dynamips/cisco-ios-site2site-ipsec-vpn-on-dynamips/75.html" title="Cisco IOS site2site ipsec vpn on dynamips">Cisco IOS site2site ipsec vpn on dynamips</a> (2)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-l2tp-voluntary-tunnel-mode-on-dynamips/74.html" title="dynamips lab:Cisco IOS l2tp voluntary tunnel mode on dynamips">dynamips lab:Cisco IOS l2tp voluntary tunnel mode on dynamips</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-easy-vpn-server-remote-on-dynamips/73.html" title="dynamips lab:Cisco IOS Easy VPN Server &amp; Remote on Dynamips">dynamips lab:Cisco IOS Easy VPN Server &amp; Remote on Dynamips</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-high-availability-ipsec-vpn-on-dynamipsloopback-address/72.html" title="dynamips lab:Cisco high availability IPSec VPN on dynamips(loopback address)">dynamips lab:Cisco high availability IPSec VPN on dynamips(loopback address)</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-adsl-pppoe-on-dynamips/70.html" title="dynamips lab:Cisco ADSL PPPOE on dynamips">dynamips lab:Cisco ADSL PPPOE on dynamips</a> (1)</li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.netemu.net/dynamips/dynamips-labcisco-l2tp-over-ipsec-with-windows-client/85.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>dynamips lab:Cisco IPSec EasyVPN &amp; DMVPN on dynamips</title>
		<link>http://www.netemu.net/dynamips/dynamips-labcisco-ipsec-easyvpn-dmvpn-on-dynamips/84.html</link>
		<comments>http://www.netemu.net/dynamips/dynamips-labcisco-ipsec-easyvpn-dmvpn-on-dynamips/84.html#comments</comments>
		<pubDate>Fri, 10 Apr 2009 01:34:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[dynamips]]></category>
		<category><![CDATA[dynamips lab]]></category>
		<category><![CDATA[ccie]]></category>
		<category><![CDATA[cisco certification]]></category>
		<category><![CDATA[cisco exam]]></category>
		<category><![CDATA[dynagen]]></category>
		<category><![CDATA[easyvpn]]></category>
		<category><![CDATA[ipsec]]></category>

		<guid isPermaLink="false">http://www.ciscosim.net/dynamips/dynamips-labcisco-ipsec-easyvpn-dmvpn-on-dynamips/81/</guid>
		<description><![CDATA[I have completed this lab on 7200 simulator, the topology is as follow: Flickr : ccie, cisco certification, cisco exam, dynagen, dynamips, easyvpn, ipsec Related Postsdynamips lab:Cisco L2TP over IPSec With windows client (2)dynamips lab:Cisco ios ssl vpn on dynamips test note2 (2)dynamips lab:CCIE topo (0)dynamips lab:Cisco ADSL PPPOE on dynamips (1)dynamips lab:Cisco ADSL PPPOA [...]]]></description>
			<content:encoded><![CDATA[<p><span lang="EN-US" style="FONT-FAMILY: 'Calibri','sans-serif'">I have completed this lab on <span style="COLOR: #b85b5a"><span lang="EN-US" style="FONT-FAMILY: 'Calibri','sans-serif'"><span style="COLOR: #000000">7200 simulator, the topology is as follow:</span></span></span></span></p>
<p><span lang="EN-US" style="FONT-FAMILY: 'Calibri','sans-serif'"><span style="COLOR: #b85b5a"><span lang="EN-US" style="FONT-FAMILY: 'Calibri','sans-serif'"><img src="http://lh5.ggpht.com/_KFnl8FWE-Rw/Sd6iNTDdf_I/AAAAAAAAAPA/z7mb62sPJdo/Cisco%20IPSec%20EasyVPN%20%26%20DMVPN%20on%20dynamips-001.jpg?imgmax=800" alt="Cisco IPSec EasyVPN &amp; DMVPN on dynamips-001.jpg" height="335" width="750"/></span></span></span></p>
<p xmlns="" class="zoundry_raven_tags">  <!-- Tag links generated by Zoundry Raven. Do not manually edit. http://www.zoundryraven.com -->  <span class="ztags"><span class="ztagspace">Flickr</span> : <a href="http://www.flickr.com/photos/tags/ccie" class="ztag" rel="tag">ccie</a>, <a href="http://www.flickr.com/photos/tags/cisco%20certification" class="ztag" rel="tag">cisco certification</a>, <a href="http://www.flickr.com/photos/tags/cisco%20exam" class="ztag" rel="tag">cisco exam</a>, <a href="http://www.flickr.com/photos/tags/dynagen" class="ztag" rel="tag">dynagen</a>, <a href="http://www.flickr.com/photos/tags/dynamips" class="ztag" rel="tag">dynamips</a>, <a href="http://www.flickr.com/photos/tags/easyvpn" class="ztag" rel="tag">easyvpn</a>, <a href="http://www.flickr.com/photos/tags/ipsec" class="ztag" rel="tag">ipsec</a></span> </p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-l2tp-over-ipsec-with-windows-client/85.html" title="dynamips lab:Cisco L2TP over IPSec With windows client">dynamips lab:Cisco L2TP over IPSec With windows client</a> (2)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-ssl-vpn-on-dynamips-test-note2/83.html" title="dynamips lab:Cisco ios ssl vpn on dynamips test note2">dynamips lab:Cisco ios ssl vpn on dynamips test note2</a> (2)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labccie-topo/66.html" title="dynamips lab:CCIE topo">dynamips lab:CCIE topo</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-adsl-pppoe-on-dynamips/70.html" title="dynamips lab:Cisco ADSL PPPOE on dynamips">dynamips lab:Cisco ADSL PPPOE on dynamips</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-adsl-pppoa-on-dynamipsi-have-completed-this-lab-on-dynamips-7200/69.html" title="dynamips lab:Cisco ADSL PPPOA on dynamipsI have completed this lab on Dynamips 7200">dynamips lab:Cisco ADSL PPPOA on dynamipsI have completed this lab on Dynamips 7200</a> (3)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labccnp-lab-for-dynamips/68.html" title="dynamips lab:ccnp lab for dynamips">dynamips lab:ccnp lab for dynamips</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labccie-security-home-lab-with-dynamips/64.html" title="dynamips lab:CCIE Security Home Lab with dynamips">dynamips lab:CCIE Security Home Lab with dynamips</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labccie-practice-lab-dynamips/41.html" title="dynamips lab:CCIE Practice LAB Dynamips">dynamips lab:CCIE Practice LAB Dynamips</a> (0)</li><li><a href="http://www.netemu.net/dynamips/cbt-ccie-practice-lab/40.html" title="CBT CCIE practice lab">CBT CCIE practice lab</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-basiccciebecome-a-ccie-with-simulator/81.html" title="dynamips basic:ccie##Become a CCIE with Simulator">dynamips basic:ccie##Become a CCIE with Simulator</a> (1)</li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.netemu.net/dynamips/dynamips-labcisco-ipsec-easyvpn-dmvpn-on-dynamips/84.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>dynamips lab:Cisco ios ssl vpn on dynamips test note2</title>
		<link>http://www.netemu.net/dynamips/dynamips-labcisco-ios-ssl-vpn-on-dynamips-test-note2/83.html</link>
		<comments>http://www.netemu.net/dynamips/dynamips-labcisco-ios-ssl-vpn-on-dynamips-test-note2/83.html#comments</comments>
		<pubDate>Fri, 10 Apr 2009 01:32:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[dynamips]]></category>
		<category><![CDATA[dynamips lab]]></category>
		<category><![CDATA[ccie]]></category>
		<category><![CDATA[cisco certification]]></category>
		<category><![CDATA[cisco exam]]></category>
		<category><![CDATA[cisco simulator]]></category>
		<category><![CDATA[dynagen]]></category>
		<category><![CDATA[ssl vpn]]></category>

		<guid isPermaLink="false">http://www.ciscosim.net/dynamips/dynamips-labcisco-ios-ssl-vpn-on-dynamips-test-note2/80/</guid>
		<description><![CDATA[Continue discussion in part 1, the topology is as follow: The Cisco SSL VPN supports on working on full-tunnel mode. In full-tunnel mode, an SSL tunnel is used to move data to and from the internal networks at the network (IP) layer. When the user logs into the SSLVPN gateway, the SSL VPN client (SVC) [...]]]></description>
			<content:encoded><![CDATA[<p>Continue discussion in part 1, the topology is as follow:</p>
<p><img src="http://lh6.ggpht.com/_KFnl8FWE-Rw/Sd6hkmGFSFI/AAAAAAAAAOo/2XJqazLkoq4/001.jpg?imgmax=576" alt="001.jpg" height="175" width="543"/></p>
<p>The Cisco SSL VPN supports on working on full-tunnel mode. In full-tunnel mode, an SSL tunnel is used to move data to and from the internal networks at the network (IP) layer. When the user logs into the SSLVPN gateway, the SSL VPN client (SVC) is automatically downloaded and installed at the end user&#8217;s PC, and the tunnel connection is established. Once the connection is established, the user has full VPN access to the corporate network.<strong>1. Preparing for Cisco Web VPN. (the same as part 1)</strong><strong><br /></strong>c7206(config)# int fa0/0c7206(config-if)# ip add 198.1.1.1 255.255.255.0</p>
<p> <span id="more-83"></span>
<p>c7206(config-if)# no shutdown</p>
<p>c7206(config-if)# exit</p>
<p>!</p>
<p>c7206(config)# int fa1/0</p>
<p>c7206(config-if)# ip add 10.10.1.1 255.255.255.0</p>
<p>c7206(config-if)# no shutdown</p>
<p>c7206(config-if)# exit</p>
<p>!</p>
<p>c7206(config)# aaa new-model</p>
<p>c7206(config)# aaa authentication login default local</p>
<p>!define the default aaa authentication list, allow the administrator to login this router, this configuration is foreign to the Web VPN. <br />!</p>
<p>c7206(config)# aaa authentication login aaa-webvpn local</p>
<p>c7206(config)# username steve6307 password cisco</p>
<p>!define the WebVPN authentication list. <br />!</p>
<p>c7206(config)# webvpn gateway mygateway</p>
<p>c7206(config-webvpn-gateway)# ip address 198.1.1.1 port 443</p>
<p>c7206(config-webvpn-gateway)# inservice</p>
<p>!define the WebVPN gateway address and port, usually the port is 443. <br />!</p>
<p>c7206(config)# webvpn context mywebvpn-context1</p>
<p>c7206(config-webvpn-context)# gateway mygateway domain group1</p>
<p>c7206(config-webvpn-context)# aaa authentication list aaa-webvpn</p>
<p>c7206(config-webvpn-context)# inservice</p>
<p>!define a WebVPN context. You must select a gateway and a aaa authentication list for each context. The domain name is very important to the configuration, because the end user will select the context by this domain name in the future. <br /><strong>2. Configure Cisco SSL VPN.</strong><strong><br /></strong>First of all, format the dynamips 7200 router disk0. <br />c7206# format disk0:Then, copy the SVC(SSL VPN Client) package to the 7200 disk0. <br />Note: the dynamips works on low efficiency, so I suggest to use FTP to copy the SVC. <br />c7206(config)# ip ftp username ciscoc7206(config)# ip ftp password cisco</p>
<p>!</p>
<p>c7206# copy ftp disk0:</p>
<p>Address or name of remote host []? 10.10.1.2</p>
<p>Source filename []? sslclient-win-1.1.2.169.pkg</p>
<p>Destination filename [sslclient-win-1.1.2.169.pkg]?</p>
<p>Accessing ftp://10.10.1.2/sslclient-win-1.1.2.169.pkg…</p>
<p>Loading sslclient-win-1.1.2.169.pkg !!</p>
<p>[OK - 415090/4096 bytes]</p>
<p>415090 bytes copied in 22.900 secs (18126 bytes/sec)Install the SVC. <br />c7206(config)# webvpn install svc disk0:/sslclient-win-1.1.2.169.pkgSSLVPN Package SSL-VPN-Client : installed successfully</p>
<p>c7206(config)# ip local pool ssl-user 192.168.10.1 192.168.10.99!define the SSL VPN user address pool. <br />!</p>
<p>c7206(config)# int loopback0</p>
<p>c7206(config-if)# ip address 192.168.10.254 255.255.255.0</p>
<p>c7206(config-if)# exit</p>
<p>!In Cisco IOS, if the SSL VPN user pool doesn&#8217;t have the save range with your inside network, you should define a loopback interface. <br />!In my lab, my inside network range is 10.10.1.0/24, and my address pool range is 192.168.10.1~99, so I need to define a loopback interface with the address 192.168.10.254. <br />!</p>
<p>c7206(config)# webvpn context mywebvpn-context1</p>
<p>c7206(config-webvpn-context)# policy group context1-policy</p>
<p>c7206(config-webvpn-group)# functions svc-enabled</p>
<p>c7206(config-webvpn-group)# svc address-pool ssl-user</p>
<p>c7206(config-webvpn-group)# exit</p>
<p>!define the group policy, allow the user to use the SSL VPN function. <br />!</p>
<p>c7206(config-webvpn-context)# default-group-policy context1-policy</p>
<p>!assign the policy as the default group policy. <br /><strong>3. Configure the SSL VPN split tunneling. (optional)</strong><strong><br /></strong>c7206(config)# webvpn context mywebvpn-context1c7206(config-webvpn-context)# policy group context1-policy</p>
<p>c7206(config-webvpn-group)# svc split include 10.10.1.0 255.255.255.0</p>
<p>!In the split tunnel list, I configured the inside network range. This means the WebVPN service will notify the SSL VPN Client to modify there local routing table, and then the client can access inside network and Internet at the same time. <br /><strong>4. Feature test.</strong><strong><br /></strong>Login WebVPN , and then I saw the page as follow:</p>
<p><img src="http://lh3.ggpht.com/_KFnl8FWE-Rw/Sd6hk-MdwcI/AAAAAAAAAOs/PPjp196OXwE/002.jpg?imgmax=512" alt="002.jpg" height="448" width="500"/></p>
<p>Then the WebVPN started the SVC install program.</p>
<p><img src="http://lh5.ggpht.com/_KFnl8FWE-Rw/Sd6hlUtFFpI/AAAAAAAAAOw/Qc09uXZ5dAs/003.jpg?imgmax=512" alt="003.jpg" height="387" width="500"/></p>
<p>After the installation, the SVC started successfully, and then I have unrestricted permission of the inside network accessing.</p>
<p><img src="http://lh4.ggpht.com/_KFnl8FWE-Rw/Sd6hlohblnI/AAAAAAAAAO0/5M_caChox6g/004.jpg?imgmax=576" alt="004.jpg" height="101" width="520"/></p>
<p>Now, I can see the SSL VPN Client info.</p>
<p><img src="http://lh3.ggpht.com/_KFnl8FWE-Rw/Sd6hmFNE_TI/AAAAAAAAAO4/FJvrSaX_1uw/005.jpg?imgmax=512" alt="005.jpg" height="334" width="432"/></p>
<p>The Cisco copyright info is as follow, aha, this is so cool!</p>
<p><img src="http://lh6.ggpht.com/_KFnl8FWE-Rw/Sd6hmV0-JVI/AAAAAAAAAO8/x-Pebf0eXbA/006.jpg?imgmax=400" alt="006.jpg" height="223" width="391"/></p>
<p xmlns="" class="zoundry_raven_tags">  <!-- Tag links generated by Zoundry Raven. Do not manually edit. http://www.zoundryraven.com -->  <span class="ztags"><span class="ztagspace">Flickr</span> : <a href="http://www.flickr.com" class="ztag" rel="tag"/>, <a href="http://www.flickr.com/photos/tags/ccie" class="ztag" rel="tag">ccie</a>, <a href="http://www.flickr.com/photos/tags/cisco%20certification" class="ztag" rel="tag">cisco certification</a>, <a href="http://www.flickr.com/photos/tags/cisco%20exam" class="ztag" rel="tag">cisco exam</a>, <a href="http://www.flickr.com/photos/tags/cisco%20simulator" class="ztag" rel="tag">cisco simulator</a>, <a href="http://www.flickr.com/photos/tags/dynagen" class="ztag" rel="tag">dynagen</a>, <a href="http://www.flickr.com/photos/tags/dynamips" class="ztag" rel="tag">dynamips</a>, <a href="http://www.flickr.com/photos/tags/ssl%20vpn" class="ztag" rel="tag">ssl vpn</a></span> </p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://www.netemu.net/dynamips/dynamips-labccie-topo/66.html" title="dynamips lab:CCIE topo">dynamips lab:CCIE topo</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-l2tp-over-ipsec-with-windows-client/85.html" title="dynamips lab:Cisco L2TP over IPSec With windows client">dynamips lab:Cisco L2TP over IPSec With windows client</a> (2)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ipsec-easyvpn-dmvpn-on-dynamips/84.html" title="dynamips lab:Cisco IPSec EasyVPN &amp; DMVPN on dynamips">dynamips lab:Cisco IPSec EasyVPN &amp; DMVPN on dynamips</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-adsl-pppoe-on-dynamips/70.html" title="dynamips lab:Cisco ADSL PPPOE on dynamips">dynamips lab:Cisco ADSL PPPOE on dynamips</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-adsl-pppoa-on-dynamipsi-have-completed-this-lab-on-dynamips-7200/69.html" title="dynamips lab:Cisco ADSL PPPOA on dynamipsI have completed this lab on Dynamips 7200">dynamips lab:Cisco ADSL PPPOA on dynamipsI have completed this lab on Dynamips 7200</a> (3)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labccnp-lab-for-dynamips/68.html" title="dynamips lab:ccnp lab for dynamips">dynamips lab:ccnp lab for dynamips</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labccie-security-home-lab-with-dynamips/64.html" title="dynamips lab:CCIE Security Home Lab with dynamips">dynamips lab:CCIE Security Home Lab with dynamips</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labccie-practice-lab-dynamips/41.html" title="dynamips lab:CCIE Practice LAB Dynamips">dynamips lab:CCIE Practice LAB Dynamips</a> (0)</li><li><a href="http://www.netemu.net/dynamips/cbt-ccie-practice-lab/40.html" title="CBT CCIE practice lab">CBT CCIE practice lab</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-basiccciebecome-a-ccie-with-simulator/81.html" title="dynamips basic:ccie##Become a CCIE with Simulator">dynamips basic:ccie##Become a CCIE with Simulator</a> (1)</li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.netemu.net/dynamips/dynamips-labcisco-ios-ssl-vpn-on-dynamips-test-note2/83.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>dynamips lab:Cisco IOS SSL VPN on dynamips test note</title>
		<link>http://www.netemu.net/dynamips/dynamips-labcisco-ios-ssl-vpn-on-dynamips-test-note/76.html</link>
		<comments>http://www.netemu.net/dynamips/dynamips-labcisco-ios-ssl-vpn-on-dynamips-test-note/76.html#comments</comments>
		<pubDate>Thu, 02 Apr 2009 07:55:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[dynamips]]></category>
		<category><![CDATA[dynamips lab]]></category>
		<category><![CDATA[cisco exam]]></category>
		<category><![CDATA[cisco simulator]]></category>
		<category><![CDATA[cisco training]]></category>
		<category><![CDATA[dynagen]]></category>
		<category><![CDATA[vpn]]></category>

		<guid isPermaLink="false">http://www.ciscosim.net/dynamips/dynamips-labcisco-ios-ssl-vpn-on-dynamips-test-note/76/</guid>
		<description><![CDATA[This test note describes how to configure Cisco SSL VPN on Cisco IOS routers. The whole lab is build on Dynamips 7200 simulator. SSL VPNs use a methodology to transport private data across the public Internet. Instead of relying upon the end user to have a configured client on an agency-managed computer, SSL VPNs use [...]]]></description>
			<content:encoded><![CDATA[<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">This test note describes how to configure Cisco SSL VPN on Cisco IOS routers. The whole lab is build on Dynamips 7200 simulator.</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">SSL VPNs use a methodology to transport private data across the public Internet. Instead of relying upon the end user to have a configured client on an agency-managed computer, SSL VPNs use SSL /HTTPS which is the secure transport mechanism built-in to all standard Web browsers. Using an SSL VPN, the connection between the user and the internal resource occurs via an HTTPS connection at the application-layer.</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">I have completed all the Cisco SSL labs on <a href="http://www.ipflow.utc.fr/blog/">Dynamips</a> 7200 simulator, the topology is as follow:</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><img src="http://lh5.ggpht.com/_KFnl8FWE-Rw/SdRvYqW-qDI/AAAAAAAAAM8/X3K3olm-0WQ/Cisco%20ios%20ssl%20vpn%20on%20dynamips-001.jpg?imgmax=512" alt="Cisco ios ssl vpn on dynamips-001.jpg" height="132" width="404"/></p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">The <a href="http://dyna-gen.sourceforge.net/">Dynagen</a> configuration is as follow:</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">
<p> <span id="more-76"></span>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"></p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">
<table cellpadding="0" cellspacing="0" style="mso-cellspacing: 0cm; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 0cm 0cm 0cm" border="1">
<tbody>
<tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes; mso-yfti-lastrow: yes">
<td width="568" style="BORDER-RIGHT: #ece9d8; PADDING-RIGHT: 0cm; BORDER-TOP: #ece9d8; PADDING-LEFT: 0cm; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 426pt; PADDING-TOP: 0cm; BORDER-BOTTOM: #ece9d8; BACKGROUND-COLOR: transparent" valign="top">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan">autostart = false <strong><br /></strong>[localhost] <strong><br /></strong>port = 7200 <strong><br /></strong>udp = 10000 <strong><br /></strong>workingdir = ..\Temp\ <strong><br /></strong><strong><br /></strong>[[router R1]] <strong><br /></strong>image = ..\IOS\c7200-advsecurityk9-mz.124-9.T1.bin <strong><br /></strong>model = 7200 <strong><br /></strong>console = 3001 <strong><br /></strong>npe = npe-400 <strong><br /></strong>ram = 128 <strong><br /></strong>confreg = 0×2142 <strong><br /></strong>exec_area = 64 <strong><br /></strong>slot0 = PA-C7200-IO-FE <strong><br /></strong>slot1 = PA-FE-TX <strong><br /></strong>f0/0 = SW1 1 <strong><br /></strong>f1/0 = SW1 2 <strong><br />[[ethsw SW1]] <br />1 = dot1q 1 <br />2 = dot1q 1 <br />3 = access 1 NIO_gen_eth:\Device\NPF_{E4377B71-C2A8-40A9-9FB6-639EE19D2F75}</strong></p>
</td>
</tr>
</tbody>
</table>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><strong>1. Preparing for Cisco Web VPN. <br /></strong> c7206(config)# int fa0/0</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-if)# ip add 198.1.1.1 255.255.255.0</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-if)# no shutdown</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-if)# exit</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">!</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config)# int fa1/0</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-if)# ip add 10.10.1.1 255.255.255.0</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-if)# no shutdown</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-if)# exit</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">!</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config)# aaa new-model</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config)# aaa authentication login default local</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">!define the default aaa authentication list, allow the administrator to login this router, this configuration is foreign to the Web VPN. <br />!</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config)# aaa authentication login aaa-webvpn local</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config)# username steve6307 password cisco</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">!define the WebVPN authentication list. <br />!</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config)# webvpn gateway mygateway</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-webvpn-gateway)# ip address 198.1.1.1 port 443</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-webvpn-gateway)# inservice</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">!define the WebVPN gateway address and port, usually the port is 443. <br />!</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config)# webvpn context mywebvpn-context1</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-webvpn-context)# gateway mygateway domain group1</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-webvpn-co<br />
ntext)# aaa authentication list aaa-webvpn</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-webvpn-context)# inservice</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">!define a WebVPN context. You must select a gateway and a aaa authentication list for each context. The domain name is very important to the configuration, because the end user will select the context by this domain name in the future. <br /><strong>2. Basic feature test(Web browsing). <br /></strong> I used Firefox to test the WebVPN feature. I entered &#8220;https://198.1.1.1/group1&#8243; in the address bar, and then I saw the WebVPN home page.</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Note: the url format is <a href="https://webvpn_gateway_addr/context_domain_name">https://webvpn_gateway_addr/context_domain_name</a></p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">I entered my username and password in the dialog box, and then click &#8220;Login&#8221;.</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><img src="http://lh4.ggpht.com/_KFnl8FWE-Rw/SdRvZdmatnI/AAAAAAAAANA/pdrUpe0zSI8/001.jpg?imgmax=512" alt="001.jpg" height="448" width="500"/></p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Now I have successfully logon the webvpn!</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><img src="http://lh5.ggpht.com/_KFnl8FWE-Rw/SdRvaZcPtrI/AAAAAAAAANE/FEKxwxLKRcs/002.jpg?imgmax=512" alt="002.jpg" height="447" width="500"/></p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">I entered the Internal Server IP address in the URL page, and then I accessed the internal server web page successfully.</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><img src="http://lh5.ggpht.com/_KFnl8FWE-Rw/SdRvbUnH-gI/AAAAAAAAANI/vY1G__ioDYM/003.jpg?imgmax=512" alt="003.jpg" height="448" width="500"/></p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><strong>3. WebVPN extended services. <br /></strong> Now, let&#8217;s talk about how to configure the webvpn extended services:</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">1. File-access feature.</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">2. Custom the url-list.</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">3. Port-forward feature.</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><strong>3.1. File-access feature <br /></strong> The file-access feature can provide browsing and file access of files on the windows file server (NetBIOS name service server).</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">To use the file access-feature, the user must have &#8220;file-access file-entry file-browsing&#8221; privilege.</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config)# webvpn context mywebvpn-context1</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-webvpn-nbnslist)# nbns-server 10.10.1.2</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-webvpn-nbnslist)# exit</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">!You must define the NetBIOS name server for IOS WebVPN. In fact, this is optional if you use the ip address to access the file server in the future. <br />!</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-webvpn-context)# policy group context1-policy</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-webvpn-group)# functions file-access</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-webvpn-group)# functions file-browse</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-webvpn-group)# functions file-entry</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-webvpn-group)# exit</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">!define the group policy for this context, assign the &#8220;file-access file-entry file-browsing&#8221; privilege. <br />!</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-webvpn-context)# default-group-policy context1-policy</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">!assign the group policy as default policy. <br /><strong>Feature test: <br /></strong> Login WebVPN again, I saw the page as follow:</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><img src="http://lh4.ggpht.com/_KFnl8FWE-Rw/SdRvcehqgvI/AAAAAAAAANM/iyXJxz9zW2o/004.jpg?imgmax=512" alt="004.jpg" height="448" width="500"/></p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">I entered &#8220;\\10.10.1.2&#8243; as the network path, and then the browser prompted me to enter my username and password to access the resources of my file server:</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><img src="http://lh4.ggpht.com/_KFnl8FWE-Rw/SdRvdaPSVoI/AAAAAAAAANQ/yIufrvKRyR0/005.jpg?imgmax=512" alt="005.jpg" height="448" width="500"/></p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-paginatio<br />
n: widow-orphan"><strong>3.2. Custom the url-list <br /></strong> c7206(config-webvpn-context)# url-list myurl</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-webvpn-url)#url-text &#8220;Home Page&#8221; url-value http://10.10.1.2</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-webvpn-url)#url-text &#8220;Site2″url-value http://10.10.1.3</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">!</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-webvpn-context)#policy group context1-policy</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-webvpn-group)#url-list myurl</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><strong>Feature test: <br /></strong> Login WebVPN again, I saw the page as follow:</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><img src="http://lh5.ggpht.com/_KFnl8FWE-Rw/SdRveGlwRDI/AAAAAAAAANU/kMpuBm7F5U8/006.jpg?imgmax=512" alt="006.jpg" height="446" width="500"/></p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><strong>3.3. Port-forward <br /></strong> Port-forward feature provides access for remote end users to client and server applications that communicate over known, fixed TCP ports. Each internal server and port number that the user can have access to has to be configured on the gateway. The entries specify the local port number and the destination server name and port number to use for TCP port forwarding.</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-webvpn-context)# port-forward myport</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-webvpn-port-fwd)# local-port 2323 remote-server 10.10.1.2 remote-port 23 description test</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-webvpn-port-fwd)# exit</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">!</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-webvpn-context)# policy group context1-policy</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">c7206(config-webvpn-group)# port-forward myport</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">!when I login the WebVPN, the browser load the JAVA App, and then I can telnet the internal server via telnet localhost 2323 port. <br style="mso-special-character: line-break"/> <br style="mso-special-character: line-break"/> <strong>Feature test: <br /></strong> Login WebVPN again, I saw the page as follow: <br style="mso-special-character: line-break"/> <br style="mso-special-character: line-break"/></p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><img src="http://lh4.ggpht.com/_KFnl8FWE-Rw/SdRvfG3rgdI/AAAAAAAAANY/JbBdkheKnl4/007.jpg?imgmax=512" alt="007.jpg" height="448" width="500"/></p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Click &#8220;Application Access&#8221;, and then the browser can load the java app.</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><img src="http://lh4.ggpht.com/_KFnl8FWE-Rw/SdRvfxcka7I/AAAAAAAAANc/s-m6GgSoO-8/008.jpg?imgmax=512" alt="008.jpg" height="387" width="500"/></p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">
<p xmlns="" class="zoundry_raven_tags">  <!-- Tag links generated by Zoundry Raven. Do not manually edit. http://www.zoundryraven.com -->  <span class="ztags"><span class="ztagspace">Flickr</span> : <a href="http://www.flickr.com/photos/tags/cisco%20exam" class="ztag" rel="tag">cisco exam</a>, <a href="http://www.flickr.com/photos/tags/cisco%20simulator" class="ztag" rel="tag">cisco simulator</a>, <a href="http://www.flickr.com/photos/tags/cisco%20training" class="ztag" rel="tag">cisco training</a>, <a href="http://www.flickr.com/photos/tags/dynagen" class="ztag" rel="tag">dynagen</a>, <a href="http://www.flickr.com/photos/tags/dynamips" class="ztag" rel="tag">dynamips</a>, <a href="http://www.flickr.com/photos/tags/vpn" class="ztag" rel="tag">vpn</a></span> </p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-easy-vpn-server-remote-on-dynamips/73.html" title="dynamips lab:Cisco IOS Easy VPN Server &amp; Remote on Dynamips">dynamips lab:Cisco IOS Easy VPN Server &amp; Remote on Dynamips</a> (0)</li><li><a href="http://www.netemu.net/dynamips/cisco-ios-site2site-ipsec-vpn-on-dynamips/75.html" title="Cisco IOS site2site ipsec vpn on dynamips">Cisco IOS site2site ipsec vpn on dynamips</a> (2)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-l2tp-voluntary-tunnel-mode-on-dynamips/74.html" title="dynamips lab:Cisco IOS l2tp voluntary tunnel mode on dynamips">dynamips lab:Cisco IOS l2tp voluntary tunnel mode on dynamips</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-high-availability-ipsec-vpn-on-dynamipsloopback-address/72.html" title="dynamips lab:Cisco high availability IPSec VPN on dynamips(loopback address)">dynamips lab:Cisco high availability IPSec VPN on dynamips(loopback address)</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-adsl-pppoe-on-dynamips/70.html" title="dynamips lab:Cisco ADSL PPPOE on dynamips">dynamips lab:Cisco ADSL PPPOE on dynamips</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-adsl-pppoa-on-dynamipsi-have-completed-this-lab-on-dynamips-7200/69.html" title="dynamips lab:Cisco ADSL PPPOA on dynamipsI have completed this lab on Dynamips 7200">dynamips lab:Cisco ADSL PPPOA on dynamipsI have completed this lab on Dynamips 7200</a> (3)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labccnp-lab-for-dynamips/68.html" title="dynamips lab:ccnp lab for dynamips">dynamips lab:ccnp lab for dynamips</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-l2tp-over-ipsec-with-windows-client/85.html" title="dynamips lab:Cisco L2TP over IPSec With windows client">dynamips lab:Cisco L2TP over IPSec With windows client</a> (2)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-ssl-vpn-on-dynamips-test-note2/83.html" title="dynamips lab:Cisco ios ssl vpn on dynamips test note2">dynamips lab:Cisco ios ssl vpn on dynamips test note2</a> (2)</li><li><a href="http://www.netemu.net/dynamips/ccieipexpert_security4_wb_sample/67.html" title="ccie##IPexpert_Security4_WB_SAMPLE">ccie##IPexpert_Security4_WB_SAMPLE</a> (1)</li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.netemu.net/dynamips/dynamips-labcisco-ios-ssl-vpn-on-dynamips-test-note/76.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Cisco IOS site2site ipsec vpn on dynamips</title>
		<link>http://www.netemu.net/dynamips/cisco-ios-site2site-ipsec-vpn-on-dynamips/75.html</link>
		<comments>http://www.netemu.net/dynamips/cisco-ios-site2site-ipsec-vpn-on-dynamips/75.html#comments</comments>
		<pubDate>Thu, 02 Apr 2009 07:44:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[dynamips]]></category>
		<category><![CDATA[dynamips lab]]></category>
		<category><![CDATA[cisco exam]]></category>
		<category><![CDATA[cisco simulator]]></category>
		<category><![CDATA[cisco training]]></category>
		<category><![CDATA[dynagen]]></category>

		<guid isPermaLink="false">http://www.ciscosim.net/dynamips/cisco-ios-site2site-ipsec-vpn-on-dynamips/75/</guid>
		<description><![CDATA[The Dynagen configuration is as follow: autostart = false [localhost] port = 7200 udp = 10000 workingdir = ..\Temp\ [[router R1]] image = ..\IOS\ c7200-advsecurityk9-mz.124-9.T1.bin model = 7200 console = 3001 npe = npe-400 ram = 128 confreg = 0×2142 exec_area = 64 mmap = false slot0 = PA-C7200-IO-FE slot1 = PA-4T f0/0 = SW1 [...]]]></description>
			<content:encoded><![CDATA[<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">The <a href="http://dyna-gen.sourceforge.net/">Dynagen</a> configuration is as follow:</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><img src="http://lh3.ggpht.com/_KFnl8FWE-Rw/SdRsxYhlnkI/AAAAAAAAAM4/IWnTUcxLDLA/Cisco%20IOS%20site2site%20ipsec%20vpn.jpg?imgmax=400" alt="Cisco IOS site2site ipsec vpn.jpg" height="85" width="396"/></p>
<p> <span id="more-75"></span><br />
<table cellpadding="0" cellspacing="0" style="mso-cellspacing: 0cm; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 0cm 0cm 0cm" border="1">
<tbody>
<tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes; mso-yfti-lastrow: yes">
<td width="568" style="BORDER-RIGHT: #ece9d8; PADDING-RIGHT: 0cm; BORDER-TOP: #ece9d8; PADDING-LEFT: 0cm; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 426pt; PADDING-TOP: 0cm; BORDER-BOTTOM: #ece9d8; BACKGROUND-COLOR: transparent" valign="top">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan">autostart = false <br />[localhost] <br />port = 7200 <br />udp = 10000 <br />workingdir = ..\Temp\ </p>
<p>[[router R1]] <br />image = ..\IOS\ c7200-advsecurityk9-mz.124-9.T1.bin <br />model = 7200 <br />console = 3001 <br />npe = npe-400 <br />ram = 128 <br />confreg = 0×2142 <br />exec_area = 64 <br />mmap = false <br />slot0 = PA-C7200-IO-FE <br />slot1 = PA-4T <br />f0/0 = SW1 1 <br />s1/1 = R3 s1/0 <br />[[router R2]] <br />image = ..\IOS\c7200-advsecurityk9-mz.124-9.T1.bin <br />model = 7200 <br />console = 3002 <br />npe = npe-400 <br />ram = 128 <br />confreg = 0×2142 <br />exec_area = 64 <br />mmap = false <br />slot0 = PA-C7200-IO-FE <br />slot1 = PA-4T <br />f0/0 = SW1 2 <br />s1/0 = R3 s1/1 </p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">[[router R3]] <br />image = ..\IOS\c3620-i-mz.122-37.bin <br />model = 3620 <br />console = 3003 <br />ram = 32 <br />confreg = 0×2142 <br />exec_area = 16 <br />mmap = false <br />slot0 = NM-1FE-TX <br />slot1 = NM-4T <br />f0/0 = SW1 3 <br />[[ethsw SW1]] <br />1 = dot1q 1 <br />2 = dot1q 1 <br />3 = dot1q 1 <br />4 = access 1 NIO_gen_eth:\Device\NPF_{E4377B71-C2A8-40A9-9FB6-639EE19D2F75}</p>
</td>
</tr>
</tbody>
</table>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><strong>1. The configuration of R1</strong></p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><strong><br /></strong></p>
<table cellpadding="0" cellspacing="0" style="mso-cellspacing: 0cm; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 0cm 0cm 0cm" border="1">
<tbody>
<tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes; mso-yfti-lastrow: yes">
<td width="568" style="BORDER-RIGHT: #ece9d8; PADDING-RIGHT: 0cm; BORDER-TOP: #ece9d8; PADDING-LEFT: 0cm; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 426pt; PADDING-TOP: 0cm; BORDER-BOTTOM: #ece9d8; BACKGROUND-COLOR: transparent" valign="top">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan">London(config)#interface Loopback0London(config-if)#ip address 10.1.1.1 255.255.255.0</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">London(config)#interface Serial1/1</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">London(config-if)#ip address 173.16.1.1 255.255.255.252</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">London(config-if)#no shutdown</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">London(config)#ip route 0.0.0.0 0.0.0.0 173.16.1.2</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">London(config)#crypto isakmp enable</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">London(config)#crypto isakmp policy 10</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">London(config-isakmp)#hash md5</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">London(config-isakmp)#authentication pre-share</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">London(config-isakmp)#encryption 3des</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">London(config-isakmp)#group 2</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">London(config)#crypto isakmp key cisco1234 address 173.16.1.5</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">London(config)#crypto ipsec transform-set ccsp esp-des esp-md5-hmac</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">London (cfg-crypto-trans)#mode tunnel</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">London(config)#crypto map cisco 10 ipsec-isakmp</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">London(config-crypto-map)#set peer 173.16.1.5</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">London(config-crypto-map)#set transform-set ccsp</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">London(config-crypto-map)#match address 101</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">London(config)#access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">London(config)#interface Serial1/1</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">London(config-if)#crypto map cisco</p>
</td>
</tr>
</tbody>
</table>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><strong>2. The configuration of R2</strong></p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><strong><br /></strong></p>
<table cellpadding="0" cellspacing="0" style="mso-cellspacing: 0cm; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 0cm 0cm 0cm" border="1">
<tbody>
<tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes; mso-yfti-lastrow: yes">
<td width="568" style="BORDER-RIGHT: #ece9d8; PADDING-RIGHT: 0cm; BORDER-TOP: #ece9d8; PADDING-LEFT: 0cm; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 426pt; PADDING-TOP: 0cm; BORDER-BOTTOM: #ece9d8; BACKGROUND-COLOR: transparent" valign="top">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan">Denver(config)#interface Loopback0Denver(config-if)#ip address 10.2.2.1 255.255.255.0</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-marg<br />
in-bottom-alt: auto; mso-pagination: widow-orphan">Denver(config)#interface Serial1/0</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Denver(config-if)#ip address 173.16.1.5 255.255.255.252</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Denver(config-if)#no shutdown</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Denver(config)#ip route 0.0.0.0 0.0.0.0 173.16.1.6</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Denver(config)#crypto isakmp enable</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Denver(config)#crypto isakmp policy 10</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Denver(config-isakmp)#hash md5</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Denver(config-isakmp)#authentication pre-share</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Denver(config-isakmp)#encryption 3des</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Denver(config-isakmp)#group 2</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Denver(config)#crypto isakmp key cisco1234 address 173.16.1.1</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Denver(config)#crypto ipsec transform-set ccsp esp-des esp-md5-hmac</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Denver(cfg-crypto-trans)#mode tunnel</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Denver(config)#crypto map cisco 10 ipsec-isakmp</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Denver(config-crypto-map)#set peer 173.16.1.1</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Denver(config-crypto-map)#set transform-set ccsp</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Denver(config-crypto-map)#match address 101</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Denver(config)#access-list 101 permit ip 10.2.2.0 0.0.0.255 10.1.1.0 0.0.0.255</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Denver(config)#interface Serial1/0</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Denver(config-if)#crypto map cisco</p>
</td>
</tr>
</tbody>
</table>
<p style="MARGIN: 0cm 0cm 0pt">
<p xmlns="" class="zoundry_raven_tags">  <!-- Tag links generated by Zoundry Raven. Do not manually edit. http://www.zoundryraven.com -->  <span class="ztags"><span class="ztagspace">Flickr</span> : <a href="http://www.flickr.com" class="ztag" rel="tag"/>, <a href="http://www.flickr.com/photos/tags/cisco%20exam" class="ztag" rel="tag">cisco exam</a>, <a href="http://www.flickr.com/photos/tags/cisco%20simulator" class="ztag" rel="tag">cisco simulator</a>, <a href="http://www.flickr.com/photos/tags/cisco%20training" class="ztag" rel="tag">cisco training</a>, <a href="http://www.flickr.com/photos/tags/dynagen" class="ztag" rel="tag">dynagen</a>, <a href="http://www.flickr.com/photos/tags/dynamips" class="ztag" rel="tag">dynamips</a></span> </p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-ssl-vpn-on-dynamips-test-note/76.html" title="dynamips lab:Cisco IOS SSL VPN on dynamips test note">dynamips lab:Cisco IOS SSL VPN on dynamips test note</a> (2)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-l2tp-voluntary-tunnel-mode-on-dynamips/74.html" title="dynamips lab:Cisco IOS l2tp voluntary tunnel mode on dynamips">dynamips lab:Cisco IOS l2tp voluntary tunnel mode on dynamips</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-easy-vpn-server-remote-on-dynamips/73.html" title="dynamips lab:Cisco IOS Easy VPN Server &amp; Remote on Dynamips">dynamips lab:Cisco IOS Easy VPN Server &amp; Remote on Dynamips</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-high-availability-ipsec-vpn-on-dynamipsloopback-address/72.html" title="dynamips lab:Cisco high availability IPSec VPN on dynamips(loopback address)">dynamips lab:Cisco high availability IPSec VPN on dynamips(loopback address)</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-adsl-pppoe-on-dynamips/70.html" title="dynamips lab:Cisco ADSL PPPOE on dynamips">dynamips lab:Cisco ADSL PPPOE on dynamips</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-adsl-pppoa-on-dynamipsi-have-completed-this-lab-on-dynamips-7200/69.html" title="dynamips lab:Cisco ADSL PPPOA on dynamipsI have completed this lab on Dynamips 7200">dynamips lab:Cisco ADSL PPPOA on dynamipsI have completed this lab on Dynamips 7200</a> (3)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labccnp-lab-for-dynamips/68.html" title="dynamips lab:ccnp lab for dynamips">dynamips lab:ccnp lab for dynamips</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-l2tp-over-ipsec-with-windows-client/85.html" title="dynamips lab:Cisco L2TP over IPSec With windows client">dynamips lab:Cisco L2TP over IPSec With windows client</a> (2)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-ssl-vpn-on-dynamips-test-note2/83.html" title="dynamips lab:Cisco ios ssl vpn on dynamips test note2">dynamips lab:Cisco ios ssl vpn on dynamips test note2</a> (2)</li><li><a href="http://www.netemu.net/dynamips/ccieipexpert_security4_wb_sample/67.html" title="ccie##IPexpert_Security4_WB_SAMPLE">ccie##IPexpert_Security4_WB_SAMPLE</a> (1)</li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.netemu.net/dynamips/cisco-ios-site2site-ipsec-vpn-on-dynamips/75.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>dynamips lab:Cisco IOS l2tp voluntary tunnel mode on dynamips</title>
		<link>http://www.netemu.net/dynamips/dynamips-labcisco-ios-l2tp-voluntary-tunnel-mode-on-dynamips/74.html</link>
		<comments>http://www.netemu.net/dynamips/dynamips-labcisco-ios-l2tp-voluntary-tunnel-mode-on-dynamips/74.html#comments</comments>
		<pubDate>Thu, 02 Apr 2009 07:41:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[dynamips]]></category>
		<category><![CDATA[dynamips lab]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[cisco exam]]></category>
		<category><![CDATA[cisco simulator]]></category>
		<category><![CDATA[cisco training]]></category>
		<category><![CDATA[dynagen]]></category>

		<guid isPermaLink="false">http://www.ciscosim.net/dynamips/dynamips-labcisco-ios-l2tp-voluntary-tunnel-mode-on-dynamips/74/</guid>
		<description><![CDATA[I have completed this lab on Dynamips 7200 simulator, the topology is as follow: The Dynagen configuration is as follow: autostart = false [localhost] port = 7200 udp = 10000 workingdir = ..\Temp\ [[router R2]] image = ..\IOS\c7200-advsecurityk9-mz.124-9.T1.bin model = 7200 console = 3002 npe = npe-400 ram = 128 confreg = 0×2142 exec_area = [...]]]></description>
			<content:encoded><![CDATA[<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">I have completed this lab on <a href="http://www.ipflow.utc.fr/blog/">Dynamips</a> 7200 simulator, the topology is as follow:</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">The <a href="http://dyna-gen.sourceforge.net/">Dynagen</a> configuration is as follow:</p>
<p> <span id="more-74"></span><br />
<table cellpadding="0" cellspacing="0" style="mso-cellspacing: 0cm; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 0cm 0cm 0cm" border="1">
<tbody>
<tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes; mso-yfti-lastrow: yes">
<td width="568" style="BORDER-RIGHT: #ece9d8; PADDING-RIGHT: 0cm; BORDER-TOP: #ece9d8; PADDING-LEFT: 0cm; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 426pt; PADDING-TOP: 0cm; BORDER-BOTTOM: #ece9d8; BACKGROUND-COLOR: transparent" valign="top">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan">autostart = false <br />[localhost] <br />port = 7200 <br />udp = 10000 <br />workingdir = ..\Temp\ </p>
<p>[[router R2]] <br />image = ..\IOS\c7200-advsecurityk9-mz.124-9.T1.bin <br />model = 7200 <br />console = 3002 <br />npe = npe-400 <br />ram = 128 <br />confreg = 0×2142 <br />exec_area = 64 <br />mmap = false <br />slot0 = PA-C7200-IO-FE <br />slot1 = PA-4T <br />f0/0 = SW1 2 <br />s1/0 = R3 s1/1 <br />[[router R3]] <br />image = ..\IOS\c3620-i-mz.122-37.bin <br />model = 3620 <br />console = 3003 <br />ram = 32 <br />confreg = 0×2142 <br />exec_area = 16 <br />mmap = false <br />slot0 = NM-1FE-TX <br />slot1 = NM-4T <br />f0/0 = SW1 3 <br />[[ethsw SW1]] <br />2 = dot1q 1 <br />3 = dot1q 1 <br />4 = access 1 NIO_gen_eth:\Device\NPF_{E4377B71-C2A8-40A9-9FB6-639EE19D2F75}</p>
</td>
</tr>
</tbody>
</table>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><strong>1. ENT LNS L2TP Configuration (R2).</strong></p>
<table cellpadding="0" cellspacing="0" style="mso-cellspacing: 0cm; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 0cm 0cm 0cm" border="1">
<tbody>
<tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes; mso-yfti-lastrow: yes">
<td width="568" style="BORDER-RIGHT: #ece9d8; PADDING-RIGHT: 0cm; BORDER-TOP: #ece9d8; PADDING-LEFT: 0cm; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 426pt; PADDING-TOP: 0cm; BORDER-BOTTOM: #ece9d8; BACKGROUND-COLOR: transparent" valign="top">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan">ENT_LNS(config)#interface FastEthernet0/0ENT_LNS(config-if)#ip address 10.10.1.1 255.255.255.0</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">ENT_LNS(config-if)#no shutdown</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">ENT_LNS(config)#interface Serial1/0</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">ENT_LNS(config-if)#ip address 173.16.1.5 255.255.255.252</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">ENT_LNS(config-if)#no shutdown</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">ENT_LNS(config)#ip route 0.0.0.0 0.0.0.0 173.16.1.6</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">ENT_LNS(config)#username cisco@cisco.com password 0 cisco</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">ENT_LNS(config)#vpdn enable</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">ENT_LNS(config)#vpdn-group myl2tp</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">ENT_LNS(config-vpdn)#accept-dialin</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">ENT_LNS(config-vpdn-acc-in)#protocol l2tp</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">ENT_LNS(config-vpdn-acc-in)#virtual-template 1</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">ENT_LNS(config-vpdn-acc-in)#exit</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">ENT_LNS(config-vpdn)#no l2tp tunnel authentication</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">ENT_LNS(config)#interface Virtual-Template1</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">ENT_LNS(config-if)#ip unnumbered FastEthernet0/0</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">ENT_LNS(config-if)#encapsulation ppp</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">ENT_LNS(config-if)#peer default ip address pool l2tp-user</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">ENT_LNS(config-if)#ppp authentication chap</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">ENT_LNS(config)#ip local pool l2tp-user 10.10.1.50 10.10.1.59</p>
</td>
</tr>
</tbody>
</table>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><strong>2. Windows Client Configuration. <br /></strong>First of all, modify the windows register as follow and restart the windows:</p>
<table cellpadding="0" cellspacing="0" style="mso-cellspacing: 0cm; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 0cm 0cm 0cm" border="1">
<tbody>
<tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes; mso-yfti-lastrow: yes">
<td width="568" style="BORDER-RIGHT: #ece9d8; PADDING-RIGHT: 0cm; BORDER-TOP: #ece9d8; PADDING-LEFT: 0cm; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 426pt; PADDING-TOP: 0cm; BORDER-BOTTOM: #ece9d8; BACKGROUND-COLOR: transparent" valign="top">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan">REGEDIT4 [HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Rasman\Parameters]</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">&#8220;ProhibitIpSec&#8221;=dword:00000001</p>
</td>
</tr>
</tbody>
</table>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">Then use the windows dialer configuration guide to complete the configuration.</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><img src="http://lh3.ggpht.com/_KFnl8FWE-Rw/SdRr_uYwT5I/AAAAAAAAAMo/lNWr92Q5QvA/Cisco%20IOS%20l2tp%20voluntary-001.jpg?imgmax=288" alt="Cisco IOS l2tp voluntary-001.jpg" height="212" width="275"/><img src="http://lh3.ggpht.com/_KFnl8FWE-Rw/SdRsAe4J__I/AAAAAAAAAMs/dyILajUwyk0/Cisco%20IOS%20l2tp%20voluntary-002.jpg?imgmax=288" alt="Cisco IOS l2tp voluntary-002.jpg" height="212" width="275"/></p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;<br />
mso-pagination: widow-orphan"><img src="http://lh6.ggpht.com/_KFnl8FWE-Rw/SdRsA6BmMrI/AAAAAAAAAMw/uaBITod_yKM/Cisco%20IOS%20l2tp%20voluntary-003.jpg?imgmax=288" alt="Cisco IOS l2tp voluntary-003.jpg" height="212" width="273"/><img src="http://lh5.ggpht.com/_KFnl8FWE-Rw/SdRsBfF_p9I/AAAAAAAAAM0/SuFxwt3ZpaY/Cisco%20IOS%20l2tp%20voluntary-004.jpg?imgmax=200" alt="Cisco IOS l2tp voluntary-004.jpg" height="200" width="191"/></p>
<p xmlns="" class="zoundry_raven_tags">  <!-- Tag links generated by Zoundry Raven. Do not manually edit. http://www.zoundryraven.com -->  <span class="ztags"><span class="ztagspace">Flickr</span> : <a href="http://www.flickr.com/photos/tags/cisco" class="ztag" rel="tag">cisco</a>, <a href="http://www.flickr.com/photos/tags/cisco%20exam" class="ztag" rel="tag">cisco exam</a>, <a href="http://www.flickr.com/photos/tags/cisco%20simulator" class="ztag" rel="tag">cisco simulator</a>, <a href="http://www.flickr.com/photos/tags/cisco%20training" class="ztag" rel="tag">cisco training</a>, <a href="http://www.flickr.com/photos/tags/dynagen" class="ztag" rel="tag">dynagen</a>, <a href="http://www.flickr.com/photos/tags/dynamips" class="ztag" rel="tag">dynamips</a></span> </p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-easy-vpn-server-remote-on-dynamips/73.html" title="dynamips lab:Cisco IOS Easy VPN Server &amp; Remote on Dynamips">dynamips lab:Cisco IOS Easy VPN Server &amp; Remote on Dynamips</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-adsl-pppoa-on-dynamipsi-have-completed-this-lab-on-dynamips-7200/69.html" title="dynamips lab:Cisco ADSL PPPOA on dynamipsI have completed this lab on Dynamips 7200">dynamips lab:Cisco ADSL PPPOA on dynamipsI have completed this lab on Dynamips 7200</a> (3)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-ssl-vpn-on-dynamips-test-note/76.html" title="dynamips lab:Cisco IOS SSL VPN on dynamips test note">dynamips lab:Cisco IOS SSL VPN on dynamips test note</a> (2)</li><li><a href="http://www.netemu.net/dynamips/cisco-ios-site2site-ipsec-vpn-on-dynamips/75.html" title="Cisco IOS site2site ipsec vpn on dynamips">Cisco IOS site2site ipsec vpn on dynamips</a> (2)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-high-availability-ipsec-vpn-on-dynamipsloopback-address/72.html" title="dynamips lab:Cisco high availability IPSec VPN on dynamips(loopback address)">dynamips lab:Cisco high availability IPSec VPN on dynamips(loopback address)</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-adsl-pppoe-on-dynamips/70.html" title="dynamips lab:Cisco ADSL PPPOE on dynamips">dynamips lab:Cisco ADSL PPPOE on dynamips</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labccnp-lab-for-dynamips/68.html" title="dynamips lab:ccnp lab for dynamips">dynamips lab:ccnp lab for dynamips</a> (1)</li><li><a href="http://www.netemu.net/dynamips/ccieipexpert_security4_wb_sample/67.html" title="ccie##IPexpert_Security4_WB_SAMPLE">ccie##IPexpert_Security4_WB_SAMPLE</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labccie-security-home-lab-with-dynamips/64.html" title="dynamips lab:CCIE Security Home Lab with dynamips">dynamips lab:CCIE Security Home Lab with dynamips</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labccie-practice-lab-dynamips/41.html" title="dynamips lab:CCIE Practice LAB Dynamips">dynamips lab:CCIE Practice LAB Dynamips</a> (0)</li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.netemu.net/dynamips/dynamips-labcisco-ios-l2tp-voluntary-tunnel-mode-on-dynamips/74.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>dynamips lab:Cisco IOS Easy VPN Server &amp; Remote on Dynamips</title>
		<link>http://www.netemu.net/dynamips/dynamips-labcisco-ios-easy-vpn-server-remote-on-dynamips/73.html</link>
		<comments>http://www.netemu.net/dynamips/dynamips-labcisco-ios-easy-vpn-server-remote-on-dynamips/73.html#comments</comments>
		<pubDate>Thu, 02 Apr 2009 07:34:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[dynamips]]></category>
		<category><![CDATA[dynamips lab]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[cisco exam]]></category>
		<category><![CDATA[cisco simulator]]></category>
		<category><![CDATA[cisco training]]></category>
		<category><![CDATA[dynagen]]></category>
		<category><![CDATA[vpn]]></category>

		<guid isPermaLink="false">http://www.ciscosim.net/dynamips/dynamips-labcisco-ios-easy-vpn-server-remote-on-dynamips/73/</guid>
		<description><![CDATA[This test note describes how to configure Cisco Remote access IPSec VPN on Cisco IOS routers. I have completed this lab on Dynamips 7200 simulator, the topology is as follow: The Dynagen configuration is as follow: autostart = false [localhost] port = 7200 udp = 10000 workingdir = ..\Temp\ [[router R1]] image = ..\IOS\ c7200-advsecurityk9-mz.124-9.T1.bin [...]]]></description>
			<content:encoded><![CDATA[<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">This test note describes how to configure Cisco Remote access IPSec VPN on Cisco IOS routers.</p>
<p>I have completed this lab on <a href="http://www.ipflow.utc.fr/blog/">Dynamips</a> 7200 simulator, the topology is as follow:</p>
<p style="TEXT-ALIGN: center"><img src="http://lh3.ggpht.com/_KFnl8FWE-Rw/SdRqZwHbT4I/AAAAAAAAAMk/9PmIa7qfu-A/Cisco%20IOS%20Easy%20VPN%20Server%20%26%20Remote%20on%20Dynamips.jpg?imgmax=400" alt="Cisco IOS Easy VPN Server &amp; Remote on Dynamips.jpg" height="132" width="400"/></p>
<p> <span id="more-73"></span>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">The <a href="http://dyna-gen.sourceforge.net/">Dynagen</a> configuration is as follow:</p>
<table cellpadding="0" cellspacing="0" style="mso-cellspacing: 0cm; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 0cm 0cm 0cm" border="1">
<tbody>
<tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes; mso-yfti-lastrow: yes">
<td width="568" style="BORDER-RIGHT: #ece9d8; PADDING-RIGHT: 0cm; BORDER-TOP: #ece9d8; PADDING-LEFT: 0cm; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 426pt; PADDING-TOP: 0cm; BORDER-BOTTOM: #ece9d8; BACKGROUND-COLOR: transparent" valign="top">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan">autostart = false <br />[localhost] <br />port = 7200 <br />udp = 10000 <br />workingdir = ..\Temp\ </p>
<p>[[router R1]] <br />image = ..\IOS\ c7200-advsecurityk9-mz.124-9.T1.bin <br />model = 7200 <br />console = 3001 <br />npe = npe-400 <br />ram = 128 <br />confreg = 0×2142 <br />exec_area = 64 <br />mmap = false <br />slot0 = PA-C7200-IO-FE <br />slot1 = PA-4T <br />f0/0 = SW1 1 <br />s1/1 = R3 s1/0 <br />[[router R2]] <br />image = ..\IOS\c3640-ik9o3s-mz.124-10.bin <br />model = 3640 <br />console = 3002 <br />ram = 128 <br />confreg = 0×2142 <br />exec_area = 64 <br />mmap = false <br />slot0 = NM-1FE-TX <br />slot1 = NM-4T <br />f0/0 = SW1 2 <br />s1/0 = R3 s1/1 <br />[[router R3]] <br />image = ..\IOS\c3620-i-mz.122-37.bin <br />model = 3620 <br />console = 3003 <br />ram = 32 <br />confreg = 0×2142 <br />exec_area = 16 <br />mmap = false <br />slot0 = NM-1FE-TX <br />slot1 = NM-4T <br />f0/0 = SW1 3 <br />[[ethsw SW1]] <br />1 = dot1q 1 <br />2 = dot1q 1 <br />3 = dot1q 1 <br />4 = access 1 NIO_gen_eth:\Device\NPF_{E4377B71-C2A8-40A9-9FB6-639EE19D2F75}</p>
</td>
</tr>
</tbody>
</table>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><strong>1. Easy VPN Server Configuration (R2). <br /></strong> server(config)# username steve password cisco!define the username and password for XAUTH, we can also use CISCO ACS to store the user information. <br />server(config)#aaa new-modelserver(config)#aaa authentication login default local</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">!define the default aaa authentication list, allow the administrator to login this router, this configuration is foreign to the ezvpn.</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">server(config)#aaa authentication login ezvpn-authentication local!define xauth authentication list. <br />server(config)#aaa authorization network ezvpn-authorization local!define the authorization list.server(config)#ip local pool ezvpn-pool 192.168.1.1 192.168.1.254server(config)#crypto isakmp policy 10server(config-isakmp)#authentication pre-shareserver(config-isakmp)#encryption 3des</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">server(config-isakmp)#hash sha</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">server(config-isakmp)#group 2</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">server(config-isakmp)#exit</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">server(config)#access-list 101 permit ip 10.10.1.0 0.0.0.255 any!define the split tunnel list, pay attention, the destination address is always &#8220;any&#8221;, and the source address is the network address of inside network.server(config)#crypto isakmp client configuration group myezvpnserver(config-isakmp-group)#key cisco1234server(config-isakmp-group)#dns 10.8.1.10</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">server(config-isakmp-group)#domain njut.edu.cn</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">server(config-isakmp-group)#pool ezvpn-pool</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">server(config-isakmp-group)#acl 101</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">!the acl is split tunnel acl. <br />server(config-isakmp-group)#save-password!allow the client save xauth password locally. <br />server(config-isakmp-group)#exitserver(config)#crypto ipsec transform-set ccsp esp-3des esp-sha-hmac server(cfg-crypto-trans)#mode tunnelserver(cfg-crypto-trans)#exit</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">server(config)#crypto dynamic-map ezvpn-dynamic-map 10 server(config-crypto-map)#set transform-set ccspserver(config-crypto-map)#reverse-route</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">server(config)#crypto map cisco client authentication list ezvpn-authentication!choose the xauth authentication list.server(config)#crypto map cisco isakmp authorization list ezvpn-authorization!choose the authorization list. <br />server(config)#crypto map cisco client configuration address respond!respond the client address request.server(config)#crypto map cisco 10 ipsec-isakmp dynamic ezvpn-dynamic-mapserver(config)#int s1/0server(config-if)#ip address 173.16.1.5 255.255.255.252server(config-if)#crypto map cisco</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">server(config)#int fa0/0server(config-if)#ip address 10.10.1.1 255.255.255.0server(config)#ip route 0.0.0.0 0.0.0.0 173.16.1.6<strong>2. Easy VPN Remote Configuration (R1). <br /></strong> remote(config)#crypto ipsec client ezvpn newlabremote(config-crypto-ezvpn)#connect auto</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">remote(config-crypto-ezvpn)#group myezvpn key cisco1234</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">remote(config-crypto-ezvpn)#mode client</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">remote(config-crypto-ezvpn)#peer 173.16.1.5</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">remote(config-crypto-ezvpn)#username steve password cisco</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">!if you didn&#8217;t open save-password option on the ezvpn server, you should issue &#8220;crypto ipsec client ezvpn xauth&#8221; command to complete xauth. <br />!</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">remote(config)#interface FastEthernet0/0</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">remote(config-if)#ip address 10.30.1.1 255.255.255.0</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">remote(config-if)#crypto ipsec client ezvpn newlab inside!</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">remote(config)#interface Serial1/1</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">remote(config-if)#ip address 173.16.1.1 255.255.255.252</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">remote(config-if)#crypto ipsec client ezvpn newlab outside</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><strong>3. Use the Cisco VPN Client Software to connect to Easy VPN Server. <br /></strong> The easy vpn server can also be connected by the Cisco VPN Client Software, you can download the software from cco site.</p>
<p xmlns="" class="zoundry_raven_tags">  <!-- Tag links generated by Zoundry Raven. Do not manually edit. http://www.zoundryraven.com -->  <span class="ztags"><span class="ztagspace">Flickr</span> : <a href="http://www.flickr.com/photos/tags/cisco" class="ztag" rel="tag">cisco</a>, <a href="http://www.flickr.com/photos/tags/cisco%20exam" class="ztag" rel="tag">cisco exam</a>, <a href="http://www.flickr.com/photos/tags/cisco%20simulator" class="ztag" rel="tag">cisco simulator</a>, <a href="http://www.flickr.com/photos/tags/cisco%20training" class="ztag" rel="tag">cisco training</a>, <a href="http://www.flickr.com/photos/tags/dynagen" class="ztag" rel="tag">dynagen</a>, <a href="http://www.flickr.com/photos/tags/dynamips" class="ztag" rel="tag">dynamips</a>, <a href="http://www.flickr.com/photos/tags/vpn" class="ztag" rel="tag">vpn</a></span> </p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-ssl-vpn-on-dynamips-test-note/76.html" title="dynamips lab:Cisco IOS SSL VPN on dynamips test note">dynamips lab:Cisco IOS SSL VPN on dynamips test note</a> (2)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-l2tp-voluntary-tunnel-mode-on-dynamips/74.html" title="dynamips lab:Cisco IOS l2tp voluntary tunnel mode on dynamips">dynamips lab:Cisco IOS l2tp voluntary tunnel mode on dynamips</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-adsl-pppoa-on-dynamipsi-have-completed-this-lab-on-dynamips-7200/69.html" title="dynamips lab:Cisco ADSL PPPOA on dynamipsI have completed this lab on Dynamips 7200">dynamips lab:Cisco ADSL PPPOA on dynamipsI have completed this lab on Dynamips 7200</a> (3)</li><li><a href="http://www.netemu.net/dynamips/cisco-ios-site2site-ipsec-vpn-on-dynamips/75.html" title="Cisco IOS site2site ipsec vpn on dynamips">Cisco IOS site2site ipsec vpn on dynamips</a> (2)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-high-availability-ipsec-vpn-on-dynamipsloopback-address/72.html" title="dynamips lab:Cisco high availability IPSec VPN on dynamips(loopback address)">dynamips lab:Cisco high availability IPSec VPN on dynamips(loopback address)</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-adsl-pppoe-on-dynamips/70.html" title="dynamips lab:Cisco ADSL PPPOE on dynamips">dynamips lab:Cisco ADSL PPPOE on dynamips</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labccnp-lab-for-dynamips/68.html" title="dynamips lab:ccnp lab for dynamips">dynamips lab:ccnp lab for dynamips</a> (1)</li><li><a href="http://www.netemu.net/dynamips/ccieipexpert_security4_wb_sample/67.html" title="ccie##IPexpert_Security4_WB_SAMPLE">ccie##IPexpert_Security4_WB_SAMPLE</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labccie-security-home-lab-with-dynamips/64.html" title="dynamips lab:CCIE Security Home Lab with dynamips">dynamips lab:CCIE Security Home Lab with dynamips</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labccie-practice-lab-dynamips/41.html" title="dynamips lab:CCIE Practice LAB Dynamips">dynamips lab:CCIE Practice LAB Dynamips</a> (0)</li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.netemu.net/dynamips/dynamips-labcisco-ios-easy-vpn-server-remote-on-dynamips/73.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>dynamips lab:Cisco high availability IPSec VPN on dynamips(loopback address)</title>
		<link>http://www.netemu.net/dynamips/dynamips-labcisco-high-availability-ipsec-vpn-on-dynamipsloopback-address/72.html</link>
		<comments>http://www.netemu.net/dynamips/dynamips-labcisco-high-availability-ipsec-vpn-on-dynamipsloopback-address/72.html#comments</comments>
		<pubDate>Thu, 02 Apr 2009 07:30:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[dynamips]]></category>
		<category><![CDATA[dynamips lab]]></category>
		<category><![CDATA[cisco exam]]></category>
		<category><![CDATA[cisco simulator]]></category>
		<category><![CDATA[cisco training]]></category>
		<category><![CDATA[dynagen]]></category>
		<category><![CDATA[ipsec vpn]]></category>

		<guid isPermaLink="false">http://www.ciscosim.net/dynamips/dynamips-labcisco-high-availability-ipsec-vpn-on-dynamipsloopback-address/72/</guid>
		<description><![CDATA[In the lab, both access link IP addresses are configured on R1 as IKE identities of R2. When R1 initiates IKE negotiation, the first peer IP address is used by IKE and becomes R2&#8242;s IKE identity for this peer. If this IKE SA times out during the negotiation, the second IP address becomes the IKE [...]]]></description>
			<content:encoded><![CDATA[<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">In the lab, both access link IP addresses are configured on R1 as IKE identities of R2. When R1 initiates IKE negotiation, the first peer IP address is used by IKE and becomes R2&#8242;s IKE identity for this peer. If this IKE SA times out during the negotiation, the second IP address becomes the IKE identity of the R2.</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><img src="http://lh3.ggpht.com/_KFnl8FWE-Rw/SdRpmQINt-I/AAAAAAAAAMg/2kVjX73YswU/Cisco%20high%20availability%20IPSec%20VPN%20on%20dynamips.jpg?imgmax=512" alt="Cisco high availability IPSec VPN on dynamips.jpg" height="148" width="500"/></p>
<p> <span id="more-72"></span>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><strong>1. R1 Configuration.</strong></p>
<table cellpadding="0" cellspacing="0" style="mso-cellspacing: 0cm; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 0cm 0cm 0cm" border="1">
<tbody>
<tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes; mso-yfti-lastrow: yes">
<td width="568" style="BORDER-RIGHT: #ece9d8; PADDING-RIGHT: 0cm; BORDER-TOP: #ece9d8; PADDING-LEFT: 0cm; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 426pt; PADDING-TOP: 0cm; BORDER-BOTTOM: #ece9d8; BACKGROUND-COLOR: transparent" valign="top">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan">R1#sh run <br />version 12.4 <br />! <br />crypto isakmp policy 10 <br />encr 3des <br />authentication pre-share <br />group 2 <br />crypto isakmp key cisco1234 address 0.0.0.0 0.0.0.0 <br />! <br />crypto ipsec transform-set ccsp esp-3des esp-sha-hmac <br />! <br />crypto map cisco 10 ipsec-isakmp <br />set peer 13.1.1.1 <br />set peer 12.1.1.1 <br />set transform-set ccsp <br />match address 101 <br />! <br />interface Loopback0 <br />ip address 10.1.1.1 255.255.255.0 <br />! <br />interface Serial1/0 <br />ip address 11.1.1.1 255.255.255.0 <br />crypto map cisco <br />! <br />router ospf 1 <br />network 11.1.1.0 0.0.0.255 area 0 <br />! <br />ip route 10.2.2.0 255.255.255.0 11.1.1.2 <br />! <br />access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255</p>
</td>
</tr>
</tbody>
</table>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><strong>2. R2 Configuration.</strong></p>
<table cellpadding="0" cellspacing="0" style="mso-cellspacing: 0cm; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 0cm 0cm 0cm" border="1">
<tbody>
<tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes; mso-yfti-lastrow: yes">
<td width="568" style="BORDER-RIGHT: #ece9d8; PADDING-RIGHT: 0cm; BORDER-TOP: #ece9d8; PADDING-LEFT: 0cm; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 426pt; PADDING-TOP: 0cm; BORDER-BOTTOM: #ece9d8; BACKGROUND-COLOR: transparent" valign="top">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan">R2#sh run <br />version 12.4 <br />! <br />crypto isakmp policy 10 <br />encr 3des <br />authentication pre-share <br />group 2 <br />crypto isakmp key cisco1234 address 0.0.0.0 0.0.0.0 <br />! <br />crypto ipsec transform-set ccsp esp-3des esp-sha-hmac <br />! <br />crypto map cisco 10 ipsec-isakmp <br />set peer 11.1.1.1 <br />set transform-set ccsp <br />match address 101 <br />! <br />interface Loopback1 <br />ip address 10.2.2.1 255.255.255.0 <br />! <br />interface Serial1/0 <br />ip address 12.1.1.1 255.255.255.0 <br />crypto map cisco <br />! <br />interface Serial1/1 <br />ip address 13.1.1.1 255.255.255.0 <br />crypto map cisco <br />! <br />router ospf 1 <br />network 12.1.1.0 0.0.0.255 area 0 <br />network 13.1.1.0 0.0.0.255 area 0 <br />! <br />ip route 10.1.1.0 255.255.255.0 11.1.1.1 <br />! <br />access-list 101 permit ip 10.2.2.0 0.0.0.255 10.1.1.0 0.0.0.255</p>
</td>
</tr>
</tbody>
</table>
<p style="MARGIN: 0cm 0cm 0pt">
<p xmlns="" class="zoundry_raven_tags">  <!-- Tag links generated by Zoundry Raven. Do not manually edit. http://www.zoundryraven.com -->  <span class="ztags"><span class="ztagspace">Flickr</span> : <a href="http://www.flickr.com" class="ztag" rel="tag"/>, <a href="http://www.flickr.com/photos/tags/cisco%20exam" class="ztag" rel="tag">cisco exam</a>, <a href="http://www.flickr.com/photos/tags/cisco%20simulator" class="ztag" rel="tag">cisco simulator</a>, <a href="http://www.flickr.com/photos/tags/cisco%20training" class="ztag" rel="tag">cisco training</a>, <a href="http://www.flickr.com/photos/tags/dynagen" class="ztag" rel="tag">dynagen</a>, <a href="http://www.flickr.com/photos/tags/dynamips" class="ztag" rel="tag">dynamips</a>, <a href="http://www.flickr.com/photos/tags/ipsec%20vpn" class="ztag" rel="tag">ipsec vpn</a></span> </p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-ssl-vpn-on-dynamips-test-note/76.html" title="dynamips lab:Cisco IOS SSL VPN on dynamips test note">dynamips lab:Cisco IOS SSL VPN on dynamips test note</a> (2)</li><li><a href="http://www.netemu.net/dynamips/cisco-ios-site2site-ipsec-vpn-on-dynamips/75.html" title="Cisco IOS site2site ipsec vpn on dynamips">Cisco IOS site2site ipsec vpn on dynamips</a> (2)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-l2tp-voluntary-tunnel-mode-on-dynamips/74.html" title="dynamips lab:Cisco IOS l2tp voluntary tunnel mode on dynamips">dynamips lab:Cisco IOS l2tp voluntary tunnel mode on dynamips</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-easy-vpn-server-remote-on-dynamips/73.html" title="dynamips lab:Cisco IOS Easy VPN Server &amp; Remote on Dynamips">dynamips lab:Cisco IOS Easy VPN Server &amp; Remote on Dynamips</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-adsl-pppoe-on-dynamips/70.html" title="dynamips lab:Cisco ADSL PPPOE on dynamips">dynamips lab:Cisco ADSL PPPOE on dynamips</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-adsl-pppoa-on-dynamipsi-have-completed-this-lab-on-dynamips-7200/69.html" title="dynamips lab:Cisco ADSL PPPOA on dynamipsI have completed this lab on Dynamips 7200">dynamips lab:Cisco ADSL PPPOA on dynamipsI have completed this lab on Dynamips 7200</a> (3)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labccnp-lab-for-dynamips/68.html" title="dynamips lab:ccnp lab for dynamips">dynamips lab:ccnp lab for dynamips</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-l2tp-over-ipsec-with-windows-client/85.html" title="dynamips lab:Cisco L2TP over IPSec With windows client">dynamips lab:Cisco L2TP over IPSec With windows client</a> (2)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-ssl-vpn-on-dynamips-test-note2/83.html" title="dynamips lab:Cisco ios ssl vpn on dynamips test note2">dynamips lab:Cisco ios ssl vpn on dynamips test note2</a> (2)</li><li><a href="http://www.netemu.net/dynamips/ccieipexpert_security4_wb_sample/67.html" title="ccie##IPexpert_Security4_WB_SAMPLE">ccie##IPexpert_Security4_WB_SAMPLE</a> (1)</li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.netemu.net/dynamips/dynamips-labcisco-high-availability-ipsec-vpn-on-dynamipsloopback-address/72.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>dynamips lab:Cisco ADSL PPPOE on dynamips</title>
		<link>http://www.netemu.net/dynamips/dynamips-labcisco-adsl-pppoe-on-dynamips/70.html</link>
		<comments>http://www.netemu.net/dynamips/dynamips-labcisco-adsl-pppoe-on-dynamips/70.html#comments</comments>
		<pubDate>Thu, 02 Apr 2009 07:20:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[dynamips]]></category>
		<category><![CDATA[dynamips lab]]></category>
		<category><![CDATA[adsl]]></category>
		<category><![CDATA[ccie]]></category>
		<category><![CDATA[cisco exam]]></category>
		<category><![CDATA[cisco simulator]]></category>
		<category><![CDATA[cisco training]]></category>
		<category><![CDATA[dynagen]]></category>
		<category><![CDATA[pppoe]]></category>

		<guid isPermaLink="false">http://www.ciscosim.net/dynamips/dynamips-labcisco-adsl-pppoe-on-dynamips/70/</guid>
		<description><![CDATA[In fact, R1 and R2 is connected by their atm interface directly. 1. CPE Configuration (R2) no ip routing ! interface FastEthernet0/0 no ip address bridge-group 1 ! interface ATM1/0 no ip address bridge-group 1 pvc 2/200 encapsulation aal5snap ! ! bridge 1 protocol ieee 2. R1 Configuration Notes: The atm card on dynamips does [...]]]></description>
			<content:encoded><![CDATA[<p><span lang="EN-US" style="FONT-FAMILY: 'Times New Roman','serif'">In fact, R1 and R2 is connected by their atm interface directly.</span></p>
<p style="TEXT-ALIGN: center"><img src="http://lh3.ggpht.com/_KFnl8FWE-Rw/SdRnNkVMjKI/AAAAAAAAAMc/sWp90lFKq8w/Cisco%20ADSL%20PPPOE%20on%20dynamips.jpg?imgmax=512" alt="Cisco ADSL PPPOE on dynamips.jpg" height="192" width="450"/></p>
<p> <span id="more-70"></span>
<p><span lang="EN-US" style="FONT-FAMILY: 'Times New Roman','serif'"><strong>1. CPE Configuration (R2)</strong></span></p>
<p><span lang="EN-US"><span style="FONT-FAMILY: 宋体">no ip routing <br />! <br />interface FastEthernet0/0 <br />no ip address <br />bridge-group 1 <br />! <br />interface ATM1/0 <br />no ip address <br />bridge-group 1 <br />pvc 2/200 <br />encapsulation aal5snap <br />! <br />! <br />bridge 1 protocol ieee</span></span></p>
<p><span lang="EN-US"><span style="FONT-FAMILY: 宋体">2. R1 Configuration <br />Notes: The atm card on dynamips does not support pppoe, we use R4 to deal with pppoe packet. So ,R1 do only bridging.</span></span></p>
<p><span lang="EN-US"><span style="FONT-FAMILY: 宋体">no ip routing <br />! <br />interface FastEthernet0/0 <br />no ip address <br />bridge-group 1 <br />! <br />interface ATM1/0 <br />no ip address <br />bridge-group 1 <br />pvc 1/100 <br />encapsulation aal5snap <br />! <br />! <br />bridge 1 protocol ieee</span></span></p>
<p><span lang="EN-US"><span style="FONT-FAMILY: 宋体">3. Aggregation Router Configuration (R4)</span></span></p>
<p><span lang="EN-US"><span style="FONT-FAMILY: 宋体">vpdn enable <br />! <br />vpdn-group 1 <br />accept-dialin <br />protocol pppoe <br />virtual-template 1 <br />! <br />username cisco password 0 cisco <br />! <br />interface Loopback0 <br />ip address 10.0.0.1 255.255.255.0 <br />! <br />interface FastEthernet0/0 <br />no ip address <br />pppoe enable <br />! <br />interface Virtual-Template1 <br />ip unnumbered Loopback0 <br />peer default ip address pool cisco <br />ppp authentication chap <br />! <br />ip local pool cisco 10.0.0.10 10.0.0.20</span></span></p>
<p><span lang="EN-US"><span style="FONT-FAMILY: 宋体">4. PPPOE client Configuration (R3)</span></span></p>
<p><span lang="EN-US"><span style="FONT-FAMILY: 宋体">vpdn enable <br />! <br />vpdn-group cisco <br />request-dialin <br />protocol pppoe <br />! <br />interface Ethernet0 <br />no ip address <br />pppoe enable <br />pppoe-client dial-pool-number 1 <br />! <br />interface Dialer0 <br />ip address negotiated <br />ip nat outside <br />encapsulation ppp <br />dialer pool 1 <br />dialer-group 1 <br />ppp chap hostname cisco <br />ppp chap password 0 cisco <br />! <br />ip route 0.0.0.0 0.0.0.0 Dialer0</span></span></p>
<p xmlns="" class="zoundry_raven_tags">  <!-- Tag links generated by Zoundry Raven. Do not manually edit. http://www.zoundryraven.com -->  <span class="ztags"><span class="ztagspace">Flickr</span> : <a href="http://www.flickr.com/photos/tags/adsl" class="ztag" rel="tag">adsl</a>, <a href="http://www.flickr.com/photos/tags/ccie" class="ztag" rel="tag">ccie</a>, <a href="http://www.flickr.com/photos/tags/cisco%20exam" class="ztag" rel="tag">cisco exam</a>, <a href="http://www.flickr.com/photos/tags/cisco%20simulator" class="ztag" rel="tag">cisco simulator</a>, <a href="http://www.flickr.com/photos/tags/cisco%20training" class="ztag" rel="tag">cisco training</a>, <a href="http://www.flickr.com/photos/tags/dynagen" class="ztag" rel="tag">dynagen</a>, <a href="http://www.flickr.com/photos/tags/dynamips" class="ztag" rel="tag">dynamips</a>, <a href="http://www.flickr.com/photos/tags/pppoe" class="ztag" rel="tag">pppoe</a></span> </p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-adsl-pppoa-on-dynamipsi-have-completed-this-lab-on-dynamips-7200/69.html" title="dynamips lab:Cisco ADSL PPPOA on dynamipsI have completed this lab on Dynamips 7200">dynamips lab:Cisco ADSL PPPOA on dynamipsI have completed this lab on Dynamips 7200</a> (3)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-ssl-vpn-on-dynamips-test-note2/83.html" title="dynamips lab:Cisco ios ssl vpn on dynamips test note2">dynamips lab:Cisco ios ssl vpn on dynamips test note2</a> (2)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-ssl-vpn-on-dynamips-test-note/76.html" title="dynamips lab:Cisco IOS SSL VPN on dynamips test note">dynamips lab:Cisco IOS SSL VPN on dynamips test note</a> (2)</li><li><a href="http://www.netemu.net/dynamips/cisco-ios-site2site-ipsec-vpn-on-dynamips/75.html" title="Cisco IOS site2site ipsec vpn on dynamips">Cisco IOS site2site ipsec vpn on dynamips</a> (2)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-l2tp-voluntary-tunnel-mode-on-dynamips/74.html" title="dynamips lab:Cisco IOS l2tp voluntary tunnel mode on dynamips">dynamips lab:Cisco IOS l2tp voluntary tunnel mode on dynamips</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-easy-vpn-server-remote-on-dynamips/73.html" title="dynamips lab:Cisco IOS Easy VPN Server &amp; Remote on Dynamips">dynamips lab:Cisco IOS Easy VPN Server &amp; Remote on Dynamips</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-high-availability-ipsec-vpn-on-dynamipsloopback-address/72.html" title="dynamips lab:Cisco high availability IPSec VPN on dynamips(loopback address)">dynamips lab:Cisco high availability IPSec VPN on dynamips(loopback address)</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labccnp-lab-for-dynamips/68.html" title="dynamips lab:ccnp lab for dynamips">dynamips lab:ccnp lab for dynamips</a> (1)</li><li><a href="http://www.netemu.net/dynamips/ccieipexpert_security4_wb_sample/67.html" title="ccie##IPexpert_Security4_WB_SAMPLE">ccie##IPexpert_Security4_WB_SAMPLE</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labccie-topo/66.html" title="dynamips lab:CCIE topo">dynamips lab:CCIE topo</a> (0)</li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.netemu.net/dynamips/dynamips-labcisco-adsl-pppoe-on-dynamips/70.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>dynamips lab:Cisco ADSL PPPOA on dynamipsI have completed this lab on Dynamips 7200</title>
		<link>http://www.netemu.net/dynamips/dynamips-labcisco-adsl-pppoa-on-dynamipsi-have-completed-this-lab-on-dynamips-7200/69.html</link>
		<comments>http://www.netemu.net/dynamips/dynamips-labcisco-adsl-pppoa-on-dynamipsi-have-completed-this-lab-on-dynamips-7200/69.html#comments</comments>
		<pubDate>Thu, 02 Apr 2009 07:16:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[dynamips]]></category>
		<category><![CDATA[dynamips lab]]></category>
		<category><![CDATA[ccie]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[cisco exam]]></category>
		<category><![CDATA[cisco simulator]]></category>
		<category><![CDATA[cisco training]]></category>
		<category><![CDATA[dynagen]]></category>

		<guid isPermaLink="false">http://www.ciscosim.net/dynamips/dynamips-labcisco-adsl-pppoa-on-dynamipsi-have-completed-this-lab-on-dynamips-7200/69/</guid>
		<description><![CDATA[simulator, the topology is as follow: In fact, R1 and R2 is connected by their atm interface directly.1. CPE Configuration (R2) interface FastEthernet0/0 ip address 172.30.1.8 255.255.255.0 ip nat inside duplex half ! interface ATM1/0 no ip address pvc 2/200 encapsulation aal5snap protocol ppp dialer dialer pool-member 1 ! interface Dialer0 ip address negotiated encapsulation [...]]]></description>
			<content:encoded><![CDATA[<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">simulator, the topology is as follow:</p>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: center; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><img src="http://lh4.ggpht.com/_KFnl8FWE-Rw/SdRmNsP5mdI/AAAAAAAAAMY/CVfTrlBr86w/Cisco%20ADSL%20PPPOA.jpg?imgmax=512" alt="Cisco ADSL PPPOA.jpg" height="132" width="450"/></p>
<p> <span id="more-69"></span>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan">In fact, R1 and R2 is connected by their atm interface directly.<strong>1. CPE Configuration (R2)</strong></p>
<table cellpadding="0" cellspacing="0" style="mso-cellspacing: 0cm; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 0cm 0cm 0cm" border="1">
<tbody>
<tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes; mso-yfti-lastrow: yes">
<td width="568" style="BORDER-RIGHT: #ece9d8; PADDING-RIGHT: 0cm; BORDER-TOP: #ece9d8; PADDING-LEFT: 0cm; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 426pt; PADDING-TOP: 0cm; BORDER-BOTTOM: #ece9d8; BACKGROUND-COLOR: transparent" valign="top">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan">interface FastEthernet0/0 <br />ip address 172.30.1.8 255.255.255.0 <br />ip nat inside <br />duplex half <br />! <br />interface ATM1/0 <br />no ip address <br />pvc 2/200 <br />encapsulation aal5snap <br />protocol ppp dialer <br />dialer pool-member 1 <br />! <br />interface Dialer0 <br />ip address negotiated <br />encapsulation ppp <br />dialer pool 1 <br />dialer-group 1 <br />ppp chap hostname cisco <br />ppp chap password 0 cisco <br />ip nat outside <br />! <br />ip route 0.0.0.0 0.0.0.0 dialer0 <br />! <br />access-list 10 permit ip 172.30.1.0 0.0.0.255 <br />ip nat inside source list 10 interface dialer 0 overload</p>
</td>
</tr>
</tbody>
</table>
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto; mso-pagination: widow-orphan"><strong>2. Aggregation Router Configuration (R1)</strong></p>
<table cellpadding="0" cellspacing="0" style="mso-cellspacing: 0cm; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 0cm 0cm 0cm" border="1">
<tbody>
<tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes; mso-yfti-lastrow: yes">
<td width="568" style="BORDER-RIGHT: #ece9d8; PADDING-RIGHT: 0cm; BORDER-TOP: #ece9d8; PADDING-LEFT: 0cm; PADDING-BOTTOM: 0cm; BORDER-LEFT: #ece9d8; WIDTH: 426pt; PADDING-TOP: 0cm; BORDER-BOTTOM: #ece9d8; BACKGROUND-COLOR: transparent" valign="top">
<p style="MARGIN: 0cm 0cm 0pt; TEXT-ALIGN: left; mso-pagination: widow-orphan">username cisco password 0 cisco <br />! <br />interface Loopback0 <br />ip address 10.0.0.1 255.255.255.0 <br />! <br />interface ATM1/0 <br />no ip address <br />pvc 1/100 <br />encapsulation aal5snap <br />protocol ppp Virtual-Template1 <br />! <br />! <br />interface Virtual-Template1 <br />ip unnumbered Loopback0 <br />peer default ip address pool cisco <br />ppp authentication chap <br />! <br />ip local pool cisco 10.0.0.2 10.0.0.6</p>
</td>
</tr>
</tbody>
</table>
<p xmlns="" class="zoundry_raven_tags">  <!-- Tag links generated by Zoundry Raven. Do not manually edit. http://www.zoundryraven.com -->  <span class="ztags"><span class="ztagspace">Flickr</span> : <a href="http://www.flickr.com" class="ztag" rel="tag"/>, <a href="http://www.flickr.com/photos/tags/ccie" class="ztag" rel="tag">ccie</a>, <a href="http://www.flickr.com/photos/tags/cisco" class="ztag" rel="tag">cisco</a>, <a href="http://www.flickr.com/photos/tags/cisco%20exam" class="ztag" rel="tag">cisco exam</a>, <a href="http://www.flickr.com/photos/tags/cisco%20simulator" class="ztag" rel="tag">cisco simulator</a>, <a href="http://www.flickr.com/photos/tags/cisco%20training" class="ztag" rel="tag">cisco training</a>, <a href="http://www.flickr.com/photos/tags/dynagen" class="ztag" rel="tag">dynagen</a>, <a href="http://www.flickr.com/photos/tags/dynamips" class="ztag" rel="tag">dynamips</a></span> </p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-l2tp-voluntary-tunnel-mode-on-dynamips/74.html" title="dynamips lab:Cisco IOS l2tp voluntary tunnel mode on dynamips">dynamips lab:Cisco IOS l2tp voluntary tunnel mode on dynamips</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-easy-vpn-server-remote-on-dynamips/73.html" title="dynamips lab:Cisco IOS Easy VPN Server &amp; Remote on Dynamips">dynamips lab:Cisco IOS Easy VPN Server &amp; Remote on Dynamips</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-adsl-pppoe-on-dynamips/70.html" title="dynamips lab:Cisco ADSL PPPOE on dynamips">dynamips lab:Cisco ADSL PPPOE on dynamips</a> (1)</li><li><a href="http://www.netemu.net/dynamips/ccieipexpert_security4_wb_sample/67.html" title="ccie##IPexpert_Security4_WB_SAMPLE">ccie##IPexpert_Security4_WB_SAMPLE</a> (1)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labccie-security-home-lab-with-dynamips/64.html" title="dynamips lab:CCIE Security Home Lab with dynamips">dynamips lab:CCIE Security Home Lab with dynamips</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labccie-practice-lab-dynamips/41.html" title="dynamips lab:CCIE Practice LAB Dynamips">dynamips lab:CCIE Practice LAB Dynamips</a> (0)</li><li><a href="http://www.netemu.net/dynamips/cbt-ccie-practice-lab/40.html" title="CBT CCIE practice lab">CBT CCIE practice lab</a> (0)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-ssl-vpn-on-dynamips-test-note2/83.html" title="dynamips lab:Cisco ios ssl vpn on dynamips test note2">dynamips lab:Cisco ios ssl vpn on dynamips test note2</a> (2)</li><li><a href="http://www.netemu.net/dynamips/dynamips-labcisco-ios-ssl-vpn-on-dynamips-test-note/76.html" title="dynamips lab:Cisco IOS SSL VPN on dynamips test note">dynamips lab:Cisco IOS SSL VPN on dynamips test note</a> (2)</li><li><a href="http://www.netemu.net/dynamips/cisco-ios-site2site-ipsec-vpn-on-dynamips/75.html" title="Cisco IOS site2site ipsec vpn on dynamips">Cisco IOS site2site ipsec vpn on dynamips</a> (2)</li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.netemu.net/dynamips/dynamips-labcisco-adsl-pppoa-on-dynamipsi-have-completed-this-lab-on-dynamips-7200/69.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
