Section 5.0: IPSec/GRE Configuration (10 points)

5.1. IPSec LAN-to-LAN Through the Firewall Using CA (5 points)

  1. Configure IPSec between R1 and R5 for Loopback10(s). Use Digital Certificates for authentication. Configure all other parameters as appropriate. If necessary, you can add one static route on R5 to achieve this task.

5.2. Multipoint GRE (5 points)

  1. Configure secure GRE tunnels on R3, R6, R7, and R8.

  2. Do not use the tunnel destination command on any routers.

  3. Use subnet 10.1.1.0/24 for tunnel interface(s).

  4. Configure only one tunnel interface on each router.

  5. Configure EIGRP AS 1 on tunnel interface(s).

  6. Advertise Loopback-9 on R6, R7, and R8 and VLAN-6 in EIGRP AS 1.

  7. No other routers should see these loopbacks.

Get CCIE Security Practice Labs now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.