crypto isakmp policy 10
encr 3des
hash sha
authentication pre-share
group 2
lifetime 86400
exit
!
crypto isakmp key [VPNKEY] address [VPNIP]
crypto ipsec transform-set L2TP esp-aes esp-md5-hmac
mode transport
exit
!
crypto map outside_map 10 ipsec-isakmp
set peer [VPNIP]
set transform-set L2TP
match address L2TP_TO_NY
exit
!
ip access-list extended L2TP_TO_NY
permit udp host 192.168.100.40 eq 1701 host [VPNIP] eq 1701
exit
!
interface GigabitEthernet8
crypto map outside_map
exit
!
pseudowire-class L2TP_CLIENT
encapsulation l2tpv2
ip local interface GigabitEthernet8
exit
!
interface Virtual-PPP1
description L2TP Tunnel
ip tcp adjust-mss 1350
ip address negotiated
ip nat outside
ip virtual-reassembly
ppp eap refuse
ppp chap hostname [MYUSERNAME]
ppp chap password 0 [MYPASSWORD]
ppp ipcp address accept
no cdp enable
pseudowire [VPNIP] 1 pw-class L2TP_CLIENT
exit
exit
!
ip route [VPNIP] 255.255.255.255 GigabitEthernet8 dhcp 1
!
ip access-list extended VPN-NAT-LIST
!exclude all communication between LAN IPs
deny ip 10.10.0.0 0.0.255.255 192.168.0.0 0.0.255.255
deny ip 192.168.0.0 0.0.255.255 10.10.0.0 0.0.255.255
deny ip 192.168.0.0 0.0.255.255 192.168.0.0 0.0.255.255
deny ip 172.16.30.0 0.0.0.255 192.168.0.0 0.0.255.255
deny ip 192.168.0.0 0.0.255.255 172.16.30.0 0.0.0.255
deny ip 172.16.30.0 0.0.0.255 10.10.0.0 0.0.255.255
deny ip 10.10.0.0 0.0.255.255 172.16.30.0 0.0.0.255
!include one host on VLAN10
permit ip host 192.168.10.77 any
!exclude my voip provider IPs
deny ip 192.168.0.0 0.0.255.255 185.45.152.0 0.0.0.255
deny ip 192.168.0.0 0.0.255.255 185.45.155.0 0.0.0.255
deny ip 192.168.0.0 0.0.255.255 37.139.38.0 0.0.0.255
deny ip 192.168.0.0 0.0.255.255 195.122.19.0 0.0.0.31
!include the entire VLAN40
permit ip 192.168.40.0 0.0.0.255 any
exit
!
route-map VPN_CLIENT_MAP permit 10
match ip address VPN-NAT-LIST
set interface Virtual-PPP1
exit
!
ip nat inside source list VPN-NAT-LIST interface Virtual-PPP1 overload
!
interface Vlan10
ip tcp adjust-mss 1200
ip nat inside
ip policy route-map VPN_CLIENT_MAP
exit
!
interface Vlan40
ip tcp adjust-mss 1200
ip nat inside
ip policy route-map VPN_CLIENT_MAP
exit
!
!
!
!finally the default route that allows the rest of my network to connect
ip route 0.0.0.0 0.0.0.0 GigabitEthernet8 dhcp 1