I. Overview:
Cisco routers have a lot of IKEV2 for the IKEV2, so you can configure them with little configuration.
Two. Basic ideas:
A. Configure flex VPN on both sides in a svti manner
B. No dynamic routing, configuration of static routes, if one side with Dvti, you need to configure static routes on both sides
Three. Test topology:
Four. Flex VPN configuration:
A.R2:
Crypto IKEv2 Keyring Keyring
Peer 202.100.2.1
Address 202.100.2.1
Pre-shared-key Cisco
Crypto IKEv2 profile Default
Match identity remote address 202.100.2.1 255.255.255.255
Authentication Remote Pre-share
Authentication Local Pre-share
Keyring Local Keyring
Interface Tunnel0
IP address 10.1.1.2 255.255.255.0
Tunnel Source FASTETHERNET0/1
Tunnel Destination 202.100.2.1
Tunnel Protection IPSec profile default
IP route 192.168.1.0 255.255.255.0 Tunnel0
B.R4:
Crypto IKEv2 Keyring Keyring
Peer 202.100.1.1
Address 202.100.1.1
Pre-shared-key Cisco
Crypto IKEv2 profile Default
Match identity remote address 202.100.1.1 255.255.255.255
Authentication Remote Pre-share
Authentication Local Pre-share
Keyring Local Keyring
Interface Tunnel0
IP address 10.1.1.4 255.255.255.0
Tunnel Source FASTETHERNET0/1
Tunnel Destination 202.100.1.1
Tunnel Protection IPSec profile default
IP Route 172.16.1.0 255.255.255.0 Tunnel0
See more highlights of this column: http://www.bianceng.cnhttp://www.bianceng.cn/Network/lyjs/