Chuyển đến nội dung chính

Lesson 12: VPN - IPsec Site-to-Site

Guide to configuring IPsec site-to-site on VyOS, differences between policy-based and route-based VPN, integration with Cisco/Palo Alto, BGP overlay lab, and troubleshooting.

VPN - IPsec Site-to-Site

Introduction to IPsec VPN on VyOS

IPsec is the industry-standard technology for secure VPN connectivity between sites. VyOS provides complete IPsec support with IKEv2, ESP, NAT-T, and VTI. This lesson covers site-to-site configuration, policy-based vs route-based designs, interoperability with other devices, and a BGP overlay lab.

IPsec fundamentals

  • IKEv2: Key negotiation protocol with stronger security than IKEv1.
  • ESP: Encapsulating Security Payload for encrypted data transport.
  • SA: Security Association containing per-tunnel security parameters.
  • Proposal: Set of encryption and authentication algorithms.
  • DH Group: Diffie-Hellman group that determines key exchange strength.

Policy-based vs Route-based (VTI) VPN

  • Policy-based: Defines which traffic is encrypted by policy selectors.
  • Route-based (VTI): Creates a virtual interface for flexible routing and supports dynamic protocols like BGP.

IPsec site-to-site configuration between 2 VyOS routers

# Tạo proposal
set vpn ipsec esp-group ESP-GROUP proposal 1 encryption aes256
set vpn ipsec esp-group ESP-GROUP proposal 1 hash sha256
set vpn ipsec ike-group IKE-GROUP proposal 1 encryption aes256
set vpn ipsec ike-group IKE-GROUP proposal 1 dh-group 14
set vpn ipsec ike-group IKE-GROUP proposal 1 hash sha256

Peer

set vpn ipsec site-to-site peer <peer-wan-ip> authentication mode pre-shared-secret set vpn ipsec site-to-site peer <peer-wan-ip> authentication pre-shared-secret '<secret>' set vpn ipsec site-to-site peer <peer-wan-ip> ike-group IKE-GROUP set vpn ipsec site-to-site peer <peer-wan-ip> esp-group ESP-GROUP set vpn ipsec site-to-site peer <peer-wan-ip> local-address '<local-wan-ip>' set vpn ipsec site-to-site peer <peer-wan-ip> tunnel 1 local prefix '192.168.1.0/24' set vpn ipsec site-to-site peer <peer-wan-ip> tunnel 1 remote prefix '192.168.2.0/24'

Route-based VPN with VTI

set interfaces vti vti0 address '10.100.100.1/30'
set vpn ipsec site-to-site peer <peer-wan-ip> vti bind vti0
set vpn ipsec site-to-site peer <peer-wan-ip> vti esp-group ESP-GROUP
set vpn ipsec site-to-site peer <peer-wan-ip> vti ike-group IKE-GROUP

IPsec interop with Cisco/Palo Alto

Synchronize proposals, pre-shared key, and local/remote subnets. Ensure NAT-T is enabled if NAT exists in the path.

Route-based VPN to Azure with BGP

set interfaces vti vti1 address '169.254.21.2/30'
set protocols bgp 65001 neighbor 169.254.21.1 remote-as 65515
set protocols bgp 65001 neighbor 169.254.21.1 update-source vti1

DMVPN dual-hub concept

VyOS supports DMVPN with multiple hubs to improve availability. The configuration is similar to route-based VPN, with additional peers.

IPsec verification and troubleshooting

show vpn ipsec sa
show vpn ipsec status
run monitor vpn ipsec

Debug a peer if the tunnel does not come up:

run monitor vpn ipsec log peer <peer-wan-ip>

Hands-on lab: Route-based IPsec VPN with BGP overlay

  1. Configure VTI interfaces on both VyOS routers.
  2. Configure IPsec peers, proposals, and pre-shared key.
  3. Set up BGP on the VTI interfaces for route exchange.
  4. Verify tunnel and routing status.
# Kiểm tra trạng thái IPsec
show vpn ipsec sa
# Kiểm tra VTI interface
show interfaces vti
# Kiểm tra BGP
show ip bgp summary

Summary

This lesson gives you a practical understanding of IPsec on VyOS, policy-based vs route-based designs, interoperability, BGP overlay labs, and real-world troubleshooting skills.