To configure a CloudBridge Connector tunnel on a Cisco IOS device, use the Cisco IOS command line interface, which is the primary user interface for configuring, monitoring, and maintaining Cisco devices.
Before you begin the CloudBridge Connector tunnel configuration on a Cisco IOS device, make sure that:
-
You have a user account with administrator credentials on the Cisco IOS device.
-
You are familiar with the Cisco IOS command line interface.
-
The Cisco IOS device is UP and running, is connected to the Internet, and is also connected to the private subnets whose traffic is to be protected over the CloudBridge Connector tunnel.
The procedures for configuring CloudBridge Connector tunnel on a Cisco IOS device might change over time, depending on the Cisco release cycle. Citrix recommends that you follow the official Cisco product documention for more information, see
Configuring IPSec VPN tunnels topic.
To configure a CloudBridge connector tunnel between a NetScaler appliance and a Cisco IOS device, perform the following tasks on the Cisco device’s IOS command line:
-
Create an IKE Policy.
-
Configure a Pre-shared key for IKE authentication.
-
Define a transform set and configure IPSec in tunnel mode.
-
Create a crypto access List
-
Create a crypto map
-
Apply the crypto Map to an interface
The examples in the following procedures create settings in Cisco IOS device Cisco-IOS-Device-1 mentioned in section "Example of CloudBridge Connector Configuration and Data Flow."
To create an IKE policy, refer to the
IKE policy pdf.
To configure a pre-shared key by using the Cisco IOS command line:
At the Cisco IOS device’s command prompt, type the following commands, starting in global configuration mode, in the order shown:
| Command |
Example |
Command Description |
| crypto isakmp identity address |
Cisco-ios-device-1(config)# crypto isakmp identity address |
Specify the ISAKMP identity (address) for the Cisco IOS device to use when communicating with the peer (NetScaler appliance) during IKE negotiations. This example specifies the address keyword, which uses IP address 203.0.113.200 (Gigabit Ethernet interface 0/1 of Cisco-IOS-Device-1) as the identity for the device. |
| crypto isakmp key keystringaddress peer-address |
Cisco-ios-device-1 (config)# crypto isakmp key examplepresharedkey address 198.51.100.100 |
Specify a pre-shared key for the IKE authentication. This example configures shared key examplepresharedkey to be used with the NetScaler appliance NS_Appliance-1 (198.51.100.100). The same pre-shared key must be configured on the NetScaler appliance for IKE authentication to be successful between the Cisco IOS device and the NetScaler appliance. |
To create a crypto access list by using the Cisco IOS command line:
At the Cisco IOS device’s command prompt, type the following command in global configuration mode, in the order shown:
| Command |
Example |
Command Description |
| access-listaccess-list-number permit IPsource source-wildcard destination destination-wildcard |
Cisco-ios-device-1(config)# access-list 111 permit ip 10.20.20.0 0.0.0.255 10.102.147.0 0.0.0.255 |
Specify conditions to determine the subnets whose IP traffic is to be protected over the CloudBridge Connector tunnel. This example configures access list 111 to protect traffic from subnets 10.20.20.0/24 (at the Cisco-IOS-Device-1 side) and 10.102.147.0/24 (at the NS_Appliance-1 side). |
To define a transform and configure IPSec tunnel mode by using the Cisco IOS command line:
At the Cisco IOS device’s command prompt, type the following commands, starting in global configuration mode, in the order shown:
| Command |
Example |
Command Description |
| crypto ipsec transform-setname ESP_Authentication_Transform ESP_Encryption_Transform Note: ESP_Authentication_Transform can take the following values: esp-sha-hmac, esp-sha256-hmac, esp-sha384-hmac, esp-sha512-hmac, esp-md5-hmac. ESP_Encryption_Transform can take the following values: esp-aes or esp-3des |
Cisco-ios-device-1(config)# crypto ipsec transform-set NS-CISCO-TS esp-sha256-hmac esp-3des |
Define a transform set and specify the ESP hash algorithm (for authentication) and the ESP encryption algorithm to be used during exchange of data between the CloudBridge Connector tunnel peers. This example defines transform set NS-CISCO-TS and specifies ESP authentication algorithm as esp-sha256-hmac, and ESP encryption algorithm as esp-3des. |
| mode tunnel |
Cisco-ios-device-1 (config-crypto-trans)# mode tunnel |
Set IPSec in tunnel mode. |
| exit |
Cisco-ios-device-1 (config-crypto-trans)# exit, Cisco-ios-device-1 (config)# |
Exit back to global configuration mode. |
To create a crypto map by using the Cisco IOS command line:
At the Cisco IOS device’s command prompt, type the following commands starting in global configuration mode, in the order shown:
| Command |
Example |
Command Description |
| crypto mapmap-name seq-num ipsec-isakmp |
Cisco-ios-device-1 (config)# crypto map NS-CISCO-CM 2 ipsec-isakmp |
Enter crypto map configuration mode, specify a sequence number for the crypto map, and configure the crypto map to use IKE to establish security associations (SAs). This example configures sequence number 2 and IKE for crypto map NS-CISCO-CM. |
| set peer ip-address |
Cisco-ios-device-1 (config-crypto-map)# set peer 172.23.2.7 |
Specify the peer (NetScaler appliance) by its IP address. This example specifies 198.51.100.100, which is the CloudBridge Connector endpoint IP address on the NetScaler appliance. |
| match addressaccess-list-id |
Cisco-ios-device-1 (config-crypto-map)# match address 111 |
Specify an extended access list. This access list specifies conditions to determine the subnets whose IP traffic is to be protected over the CloudBridge Connector tunnel. This example specifies access list 111. |
| set transform-set transform-set-name |
Cisco-ios-device-1 (config-crypto-map)# set transform-set NS-CISCO-TS |
Specify which transform sets are allowed for this crypto map entry. This example specifies transform set NS-CISCO-TS. |
| exit |
Cisco-ios-device-1 (config-crypto-map)# exit |
|
To apply a crypto map to an interface by using the Cisco IOS command line:
At the Cisco IOS device’s command prompt, type the following commands starting in global configuration mode, in the order shown:
| Command |
Example |
Command Description |
| interfaceinterface-ID |
Cisco-ios-device-1(config)# interface GigabitEthernet 0/1 |
Specify a physical interface to which to apply the crypto map and enter interface configuration mode. This example specifies Gigabit Ethernet interface 0/1 of the Cisco device Cisco-IOS-Device-1. IP address 203.0.113.200 is already set to this interface. |
| crypto mapmap-name |
Cisco-ios-device-1 (config-if)# crypto map NS-CISCO-CM |
Apply the crypto map to the physical interface. This example applies crypto map NS-CISCO-CM. |
| exit |
Cisco-ios-device-1 (config-if)# exit, Cisco-ios-device-1 (config)# |
Exit back to global configuration mode. |