! โโ 1. IKEv2 Proposal โโโโโโโโโโโโโโโโโโโโโ crypto ikev2 proposal PROP-IKEv2 encryption aes-cbc-256 integrity sha256 group 14 ! โโ 2. IKEv2 Policy โโโโโโโโโโโโโโโโโโโโโโโโ crypto ikev2 policy POL-IKEv2 proposal PROP-IKEv2 ! โโ 3. Keyring (PSK) โโโโโโโโโโโโโโโโโโโโโโโ crypto ikev2 keyring KR-IKEv2 peer R2 address 10.0.0.2 pre-shared-key MySecret123 ! โโ 4. IKEv2 Profile โโโโโโโโโโโโโโโโโโโโโโโ crypto ikev2 profile PROF-IKEv2 match identity remote address 10.0.0.2 255.255.255.255 authentication remote pre-share authentication local pre-share keyring local KR-IKEv2 ! โโ 5. IPsec Transform-Set (Child SA) โโโโโโ crypto ipsec transform-set TS-ESP esp-aes 256 esp-sha256-hmac mode tunnel ! โโ 6. IPsec Profile โโโโโโโโโโโโโโโโโโโโโโโ crypto ipsec profile IPSEC-PROF set transform-set TS-ESP set ikev2-profile PROF-IKEv2 ! โโ 7. Interface VTI โโโโโโโโโโโโโโโโโโโโโโโ interface Tunnel0 ip address 172.16.0.1 255.255.255.252 tunnel source GigabitEthernet0/0 tunnel destination 10.0.0.2 tunnel mode ipsec ipv4 tunnel protection ipsec profile IPSEC-PROF ! โโ 8. Route statique โโโโโโโโโโโโโโโโโโโโโโ ip route 192.168.2.0 255.255.255.0 Tunnel0
! โโ 1. IKEv2 Proposal โโโโโโโโโโโโโโโโโโโโโ crypto ikev2 proposal PROP-IKEv2 encryption aes-cbc-256 integrity sha256 group 14 ! โโ 2. IKEv2 Policy โโโโโโโโโโโโโโโโโโโโโโโโ crypto ikev2 policy POL-IKEv2 proposal PROP-IKEv2 ! โโ 3. Keyring (PSK) โโโโโโโโโโโโโโโโโโโโโโโ crypto ikev2 keyring KR-IKEv2 peer R1 address 10.0.0.1 pre-shared-key MySecret123 ! โโ 4. IKEv2 Profile โโโโโโโโโโโโโโโโโโโโโโโ crypto ikev2 profile PROF-IKEv2 match identity remote address 10.0.0.1 255.255.255.255 authentication remote pre-share authentication local pre-share keyring local KR-IKEv2 ! โโ 5. IPsec Transform-Set (Child SA) โโโโโโ crypto ipsec transform-set TS-ESP esp-aes 256 esp-sha256-hmac mode tunnel ! โโ 6. IPsec Profile โโโโโโโโโโโโโโโโโโโโโโโ crypto ipsec profile IPSEC-PROF set transform-set TS-ESP set ikev2-profile PROF-IKEv2 ! โโ 7. Interface VTI โโโโโโโโโโโโโโโโโโโโโโโ interface Tunnel0 ip address 172.16.0.2 255.255.255.252 tunnel source GigabitEthernet0/0 tunnel destination 10.0.0.1 tunnel mode ipsec ipv4 tunnel protection ipsec profile IPSEC-PROF ! โโ 8. Route statique โโโโโโโโโโโโโโโโโโโโโโ ip route 192.168.1.0 255.255.255.0 Tunnel0