SlideShare a Scribd company logo
GET VPN -Multicast
Dhruv Sharma
6/30/2021
Introduction
In this session we will review below points:
• Building blocks in setting up GETVPN for Multicast
• Review the implementation steps on KS and Group members
• Lab fun
6/30/2021
Network Topology
6/30/2021
Introduction
• In Ipsec VPN where new IP Address were added along with the outer header as shown below, in
tunnel mode.
• With GET VPN it ensure the private address is preserved. Which makes GET VPN, usable only on
the private LAN. We cannot use Transport Mode as it might cause fragmentation errors.
6/30/2021
Introduction
• Two Types of Keys:
• KEK ( Key Encryption Key)
• TEK (Traffic Encryption Key)
• When the lifetime expires, we can configure our VPN to send rekey messages in either unicast (
with acknowledgement) or multicast mode ( no acknowledgement).
6/30/2021
• KS setup
6/30/2021
KS configuration – Step 1
• VPN Configuration
crypto isakmp policy 1
encr aes
authentication pre-share
group 2
crypto isakmp key cisco address 0.0.0.0
!
crypto ipsec transform-set ra-set esp-aes esp-sha-hmac
mode tunnel
!
ip access-list extended babi
permit ip 10.0.0.0 0.255.255.255 10.0.0.0 0.255.255.255
!
crypto ipsec profile key1-profile
set transform-set ra-set
6/30/2021
KS configuration – step 2
• Multicast configuration
!
ip multicast-routing distributed
!
interface GigabitEthernet1
ip address 11.11.11.1 255.0.0.0
ip pim dense-mode
negotiation auto
!
ip access-list extended multi
permit ip host 11.11.11.1 host 239.1.1.1
!
6/30/2021
KS configuration – step 3
• GDOI Configuration
!
crypto gdoi group dhruv
identity number 123
server local
rekey address ipv4 multi
rekey authentication mypubkey rsa rsa-keys
sa ipsec 10
profile key1-profile
match address ipv4 babi
replay counter window-size 64
no tag
address ipv4 11.11.11.1
6/30/2021
Crypto key generate rsa lablel rsa-keys mod 1024
• ISP setup
6/30/2021
ISP Configuration
• ISP Configuration
ip multicast-routing distributed
!
interface GigabitEthernet1
ip address 11.11.11.100 255.0.0.0
ip pim dense-mode
negotiation auto
!
interface GigabitEthernet2
ip address 12.12.12.100 255.0.0.0
ip pim dense-mode
negotiation auto
!
interface GigabitEthernet3
ip address 13.13.13.100 255.0.0.0
ip pim dense-mode
negotiation auto
!
6/30/2021
• GM setup
6/30/2021
GM Configuration Step 1
• VPN Configuration
crypto isakmp policy 1
encr aes
authentication pre-share
group 2
crypto isakmp key cisco address 11.11.11.1
!
crypto ipsec transform-set cow-set esp-aes esp-sha-hmac
mode tunnel
!
6/30/2021
GM Configuration Step 2
• Multicast Configuration
ip multicast-routing distributed
!
interface GigabitEthernet1
ip address 12.12.12.1 255.0.0.0
ip pim dense-mode
ip igmp join-group 239.1.1.1
negotiation auto
!
6/30/2021
GM Configuration Step 3
• GDOI Configuration
!
crypto gdoi group gm1
identity number 123
server address ipv4 11.11.11.1
crypto map crypto 10 gdoi
set group gm1
!
interface GigabitEthernet1
crypto map crypto
6/30/2021
• Testing
6/30/2021
Testing
• Ping Test
6/30/2021
Testing
• Gdoi group status
6/30/2021
Testing
• VPN status
6/30/2021
Testing
6/30/2021
• Lab Configure
6/30/2021
6/30/2021

More Related Content

PPTX
Setting up VPN between F5 LTM & ASA
PPTX
CCNA Inter VLAN Routing
PPTX
Vandyke SecureCRT tips and tricks
PPTX
CCNA Routing Basics
PPTX
Cisco ASR 1001-X Router
PPTX
CCNA point to point
PDF
VPNaaS in Neutron
PPTX
TCLSH and Macro Ping Test on Cisco Routers and Switches
Setting up VPN between F5 LTM & ASA
CCNA Inter VLAN Routing
Vandyke SecureCRT tips and tricks
CCNA Routing Basics
Cisco ASR 1001-X Router
CCNA point to point
VPNaaS in Neutron
TCLSH and Macro Ping Test on Cisco Routers and Switches

What's hot (20)

PDF
Routed Provider Networks on OpenStack
PPTX
Networking in the cloud
PPTX
Unleashing the Power of Fabric Orchestrating New Performance Features for SR-...
PPTX
CCNA Network Monitoring
PPTX
Final presentation phases1_2_3
DOCX
Nexus 1000 v access guide
PPTX
Securing management, control & data plane
PPTX
MTU (maximum transmission unit) & MRU (maximum receive unit)
PPTX
OTV Configuration
PPTX
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
PDF
Migrating from OSPF to IS-IS by Philip Smith
PPS
Iuwne10 S02 L07
PPTX
NETWORKERS HOME Cisco UCS PPT .
TXT
Configuracao de switch
PDF
ElasticISP
PPTX
Salt for Network Engineers
PDF
Class 3
PDF
Ftp configuration in cisco packet tracer
Routed Provider Networks on OpenStack
Networking in the cloud
Unleashing the Power of Fabric Orchestrating New Performance Features for SR-...
CCNA Network Monitoring
Final presentation phases1_2_3
Nexus 1000 v access guide
Securing management, control & data plane
MTU (maximum transmission unit) & MRU (maximum receive unit)
OTV Configuration
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
Migrating from OSPF to IS-IS by Philip Smith
Iuwne10 S02 L07
NETWORKERS HOME Cisco UCS PPT .
Configuracao de switch
ElasticISP
Salt for Network Engineers
Class 3
Ftp configuration in cisco packet tracer
Ad

Similar to Get vpn multicast for CCIE Security (20)

PPT
Vpn(4)
PPT
Vpn site to site
PDF
Sharing your-internet-connection-on-linux
PPT
Cisco Router As A Vpn Server
PPT
Ciscorouterasavpnserver 100218045815-phpapp01
PDF
FlexVPNLabHandbook-SAMPLE
PDF
P&G BT Global Services - LLD Final Revision Year 2008.
PDF
Deployment guide c07_554713
PDF
Implementation of DNS Anycast - a case study
PDF
Openstack Summit Vancouver 2018 - Multicloud Networking
PPT
Day 18 2 serial point to-point encapsulation
PDF
Lksn2017 itnsa modul2
PPTX
EMEA Airheads- Manage Devices at Branch Office (BOC)
PDF
Implementing an IPv6 Enabled Environment for a Public Cloud Tenant
PDF
See what happened with real time kvm when building real time cloud pezhang@re...
PPT
Chapter 2 overview
PDF
GeoVision : CCTV Solutions : Multicast solutions
PDF
Ch8 - Implementing Virtual Private Networks
PDF
IoT Secure Bootsrapping : ideas
Vpn(4)
Vpn site to site
Sharing your-internet-connection-on-linux
Cisco Router As A Vpn Server
Ciscorouterasavpnserver 100218045815-phpapp01
FlexVPNLabHandbook-SAMPLE
P&G BT Global Services - LLD Final Revision Year 2008.
Deployment guide c07_554713
Implementation of DNS Anycast - a case study
Openstack Summit Vancouver 2018 - Multicloud Networking
Day 18 2 serial point to-point encapsulation
Lksn2017 itnsa modul2
EMEA Airheads- Manage Devices at Branch Office (BOC)
Implementing an IPv6 Enabled Environment for a Public Cloud Tenant
See what happened with real time kvm when building real time cloud pezhang@re...
Chapter 2 overview
GeoVision : CCTV Solutions : Multicast solutions
Ch8 - Implementing Virtual Private Networks
IoT Secure Bootsrapping : ideas
Ad

More from Dhruv Sharma (17)

PPTX
RAVPN EAP-IKEv2 VPN.pptx
PPTX
Load Balance with NSX-T.pptx
PPTX
NSX_Troubleshooting.pptx
PPTX
ASA VPN_Certificate authentication_ISE Authorization.pptx
PPTX
Setting up CDP (Cisco Discovery Protocol) between Cisco IOS and VMware Virtua...
PPTX
Routebased-Policybased VPN.pptx
PPTX
Ansible Network Automation session1
PPTX
Setting up Cisco WSA Proxy in Transparent and Explicit Mode
PPTX
Factory setup wsa_9.2_v1.0
PPTX
Tacacs+ with ise 2.4_ CCIE
PPTX
Route tags with OSPF
PPTX
Aci vmware integration_youtube
PPTX
Introduction to nexux from zero to Hero
PPTX
Cisco umbrella youtube
PPTX
GTM vs AWS Route 53 with Cisco umbrella
PPTX
Unquoted service path exploitation
PPTX
Getting started kali linux
RAVPN EAP-IKEv2 VPN.pptx
Load Balance with NSX-T.pptx
NSX_Troubleshooting.pptx
ASA VPN_Certificate authentication_ISE Authorization.pptx
Setting up CDP (Cisco Discovery Protocol) between Cisco IOS and VMware Virtua...
Routebased-Policybased VPN.pptx
Ansible Network Automation session1
Setting up Cisco WSA Proxy in Transparent and Explicit Mode
Factory setup wsa_9.2_v1.0
Tacacs+ with ise 2.4_ CCIE
Route tags with OSPF
Aci vmware integration_youtube
Introduction to nexux from zero to Hero
Cisco umbrella youtube
GTM vs AWS Route 53 with Cisco umbrella
Unquoted service path exploitation
Getting started kali linux

Recently uploaded (20)

PDF
O7-L3 Supply Chain Operations - ICLT Program
PDF
Saundersa Comprehensive Review for the NCLEX-RN Examination.pdf
PPTX
Microbial diseases, their pathogenesis and prophylaxis
PPTX
BOWEL ELIMINATION FACTORS AFFECTING AND TYPES
PPTX
Pharmacology of Heart Failure /Pharmacotherapy of CHF
PDF
FourierSeries-QuestionsWithAnswers(Part-A).pdf
PDF
Basic Mud Logging Guide for educational purpose
PDF
STATICS OF THE RIGID BODIES Hibbelers.pdf
PDF
Origin of periodic table-Mendeleev’s Periodic-Modern Periodic table
PPTX
The Healthy Child – Unit II | Child Health Nursing I | B.Sc Nursing 5th Semester
PDF
VCE English Exam - Section C Student Revision Booklet
PPTX
school management -TNTEU- B.Ed., Semester II Unit 1.pptx
PPTX
Institutional Correction lecture only . . .
PDF
2.FourierTransform-ShortQuestionswithAnswers.pdf
PPTX
Renaissance Architecture: A Journey from Faith to Humanism
PDF
ANTIBIOTICS.pptx.pdf………………… xxxxxxxxxxxxx
PDF
Anesthesia in Laparoscopic Surgery in India
PDF
BÀI TẬP BỔ TRỢ 4 KỸ NĂNG TIẾNG ANH 9 GLOBAL SUCCESS - CẢ NĂM - BÁM SÁT FORM Đ...
PPTX
human mycosis Human fungal infections are called human mycosis..pptx
PDF
01-Introduction-to-Information-Management.pdf
O7-L3 Supply Chain Operations - ICLT Program
Saundersa Comprehensive Review for the NCLEX-RN Examination.pdf
Microbial diseases, their pathogenesis and prophylaxis
BOWEL ELIMINATION FACTORS AFFECTING AND TYPES
Pharmacology of Heart Failure /Pharmacotherapy of CHF
FourierSeries-QuestionsWithAnswers(Part-A).pdf
Basic Mud Logging Guide for educational purpose
STATICS OF THE RIGID BODIES Hibbelers.pdf
Origin of periodic table-Mendeleev’s Periodic-Modern Periodic table
The Healthy Child – Unit II | Child Health Nursing I | B.Sc Nursing 5th Semester
VCE English Exam - Section C Student Revision Booklet
school management -TNTEU- B.Ed., Semester II Unit 1.pptx
Institutional Correction lecture only . . .
2.FourierTransform-ShortQuestionswithAnswers.pdf
Renaissance Architecture: A Journey from Faith to Humanism
ANTIBIOTICS.pptx.pdf………………… xxxxxxxxxxxxx
Anesthesia in Laparoscopic Surgery in India
BÀI TẬP BỔ TRỢ 4 KỸ NĂNG TIẾNG ANH 9 GLOBAL SUCCESS - CẢ NĂM - BÁM SÁT FORM Đ...
human mycosis Human fungal infections are called human mycosis..pptx
01-Introduction-to-Information-Management.pdf

Get vpn multicast for CCIE Security

  • 1. GET VPN -Multicast Dhruv Sharma 6/30/2021
  • 2. Introduction In this session we will review below points: • Building blocks in setting up GETVPN for Multicast • Review the implementation steps on KS and Group members • Lab fun 6/30/2021
  • 4. Introduction • In Ipsec VPN where new IP Address were added along with the outer header as shown below, in tunnel mode. • With GET VPN it ensure the private address is preserved. Which makes GET VPN, usable only on the private LAN. We cannot use Transport Mode as it might cause fragmentation errors. 6/30/2021
  • 5. Introduction • Two Types of Keys: • KEK ( Key Encryption Key) • TEK (Traffic Encryption Key) • When the lifetime expires, we can configure our VPN to send rekey messages in either unicast ( with acknowledgement) or multicast mode ( no acknowledgement). 6/30/2021
  • 7. KS configuration – Step 1 • VPN Configuration crypto isakmp policy 1 encr aes authentication pre-share group 2 crypto isakmp key cisco address 0.0.0.0 ! crypto ipsec transform-set ra-set esp-aes esp-sha-hmac mode tunnel ! ip access-list extended babi permit ip 10.0.0.0 0.255.255.255 10.0.0.0 0.255.255.255 ! crypto ipsec profile key1-profile set transform-set ra-set 6/30/2021
  • 8. KS configuration – step 2 • Multicast configuration ! ip multicast-routing distributed ! interface GigabitEthernet1 ip address 11.11.11.1 255.0.0.0 ip pim dense-mode negotiation auto ! ip access-list extended multi permit ip host 11.11.11.1 host 239.1.1.1 ! 6/30/2021
  • 9. KS configuration – step 3 • GDOI Configuration ! crypto gdoi group dhruv identity number 123 server local rekey address ipv4 multi rekey authentication mypubkey rsa rsa-keys sa ipsec 10 profile key1-profile match address ipv4 babi replay counter window-size 64 no tag address ipv4 11.11.11.1 6/30/2021 Crypto key generate rsa lablel rsa-keys mod 1024
  • 11. ISP Configuration • ISP Configuration ip multicast-routing distributed ! interface GigabitEthernet1 ip address 11.11.11.100 255.0.0.0 ip pim dense-mode negotiation auto ! interface GigabitEthernet2 ip address 12.12.12.100 255.0.0.0 ip pim dense-mode negotiation auto ! interface GigabitEthernet3 ip address 13.13.13.100 255.0.0.0 ip pim dense-mode negotiation auto ! 6/30/2021
  • 13. GM Configuration Step 1 • VPN Configuration crypto isakmp policy 1 encr aes authentication pre-share group 2 crypto isakmp key cisco address 11.11.11.1 ! crypto ipsec transform-set cow-set esp-aes esp-sha-hmac mode tunnel ! 6/30/2021
  • 14. GM Configuration Step 2 • Multicast Configuration ip multicast-routing distributed ! interface GigabitEthernet1 ip address 12.12.12.1 255.0.0.0 ip pim dense-mode ip igmp join-group 239.1.1.1 negotiation auto ! 6/30/2021
  • 15. GM Configuration Step 3 • GDOI Configuration ! crypto gdoi group gm1 identity number 123 server address ipv4 11.11.11.1 crypto map crypto 10 gdoi set group gm1 ! interface GigabitEthernet1 crypto map crypto 6/30/2021
  • 18. Testing • Gdoi group status 6/30/2021