• In the previous lesson, you saw what IPsec protects and how IKE negotiates the tunnel in two phases.
    In this lesson, you build that tunnel between two sites and verify each phase on the router.

    Before you can configure IPsec, the underlay must be working.
    This lab uses the same topology and addressing as the GRE lesson.

    ipsec topology cisco configuration lab

    Figure 1 - IPsec lab topology

    The routing is also identical: static routes on ISP1 and ISP2, and default routes on R1 and R2.

    Static routes configured on ISP routers for GRE lab connectivity

    Figure 2 - Routing configuration on the IPsec topology

    Here is a quick recap of the routing configuration:

    ISP1# conf t
    Enter configuration commands, one per line.  End with CNTL/Z.
    ISP1(config)# ip route 203.0.113.8 255.255.255.252 203.0.113.6

    static route configuration on ISP2

    Figure 3 - ISP2 static routing

    ISP2# conf t
    Enter configuration commands, one per line.  End with CNTL/Z.
    ISP2(config)# ip route 203.0.113.0 255.255.255.252 203.0.113.5

    Default route configuration to reach GRE tunnel destination

    Figure 4 - Default route configuration

    R1(config)# ip route 0.0.0.0 0.0.0.0 203.0.113.2
    R2(config)# ip route 0.0.0.0 0.0.0.0 203.0.113.9

    At this point, R1 and R2 can reach each other's WAN interfaces through the ISP network.
    Your underlay is ready. Now you can build the IPsec tunnel on top of it.

    Answer the question below

    Why must R1 and R2 have WAN reachability before configuring IPsec?