{"id":171,"date":"2015-08-21T08:18:09","date_gmt":"2015-08-21T08:18:09","guid":{"rendered":"http:\/\/www.safekom.pl\/blog\/?p=171"},"modified":"2015-08-21T08:18:28","modified_gmt":"2015-08-21T08:18:28","slug":"lab-ipsec-juniper-srx-cisco-router","status":"publish","type":"post","link":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ipsec-juniper-srx-cisco-router\/","title":{"rendered":"Lab &#8211; IPSEC Juniper SRX &#8211; Cisco router"},"content":{"rendered":"<p>Dzi\u015b postanowi\u0142em opisa\u0107 troch\u0119 labowania, temat ostatnio bardzo mocno przerabiany IPSEC. Poni\u017cej opisz\u0119 wariant policy base vpn, kt\u00f3ry jest bardzo elastyczny.<\/p>\n<h3>Za\u0142o\u017cenia:<\/h3>\n<p><a href=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/vpn_srx_cisco_pb.png\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"285\" data-permalink=\"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ipsec-juniper-srx-cisco-router\/attachment\/vpn_srx_cisco_pb\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/vpn_srx_cisco_pb.png?fit=639%2C146&amp;ssl=1\" data-orig-size=\"639,146\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"vpn_srx_cisco_pb\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/vpn_srx_cisco_pb.png?fit=639%2C146&amp;ssl=1\" class=\"alignnone wp-image-285\" src=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/vpn_srx_cisco_pb.png?resize=678%2C155\" alt=\"vpn_srx_cisco_pb\" width=\"678\" height=\"155\" srcset=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/vpn_srx_cisco_pb.png?w=639&amp;ssl=1 639w, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/vpn_srx_cisco_pb.png?resize=300%2C69&amp;ssl=1 300w\" sizes=\"auto, (max-width: 678px) 100vw, 678px\" \/><\/a><\/p>\n<table>\n<tbody>\n<tr>\n<td>Faza 1<\/td>\n<td>aes256 sha-1 pfs g2 3600s<\/td>\n<\/tr>\n<tr>\n<td>Faza 2<\/td>\n<td>aes256 sha-1 pfs g2 3600s<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table>\n<tbody>\n<tr>\n<td><\/td>\n<td>Cisco<\/td>\n<td>Juniper SRX<\/td>\n<\/tr>\n<tr>\n<td>Sieci kt\u00f3re b\u0119d\u0105 podlega\u0142y szyfrowaniu<\/td>\n<td>172.16.10.0\/24<\/td>\n<td>10.10.10.0\/24<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table>\n<tbody>\n<tr>\n<td><\/td>\n<td>Cisco<\/td>\n<td>Juniper SRX<\/td>\n<\/tr>\n<tr>\n<td>Interfejs z adresem tzw. publicznym<\/td>\n<td>192.168.1.201\/24<\/td>\n<td>192.168.1.2\/24<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Konfiguracja Cisco<\/h3>\n<p>Logujemy si\u0119 do Cisco:<\/p>\n<pre class=\"lang:sh decode:true \">r_cisco_safekom&gt;en\r\nr_cisco_safekom#conf t\r\nEnter configuration commands, one per line.  End with CNTL\/Z.<\/pre>\n<p>konfiguracja fazy 1<\/p>\n<pre class=\"lang:sh decode:true \">r_cisco_safekom(config)#crypto isakmp policy 1\r\nr_cisco_safekom(config-isakmp)#encryption aes 256 \r\nr_cisco_safekom(config-isakmp)#hash sha\r\nr_cisco_safekom(config-isakmp)#authentication pre-share \r\nr_cisco_safekom(config-isakmp)#group 2\r\nr_cisco_safekom(config-isakmp)#lifetime 3600\r\nr_cisco_safekom(config-isakmp)#exit  \r\nr_cisco_safekom(config)#crypto isakmp key Qwert67890! address 192.168.1.2<\/pre>\n<p>konfiguracja fazy 2<\/p>\n<pre class=\"lang:sh decode:true\">r_cisco_safekom(config)#ip access-list extended VPN-SRX\r\nr_cisco_safekom(config-ext-nacl)#permit ip 172.16.10.0 0.0.0.255 10.10.10.0 0.0.0.255 \r\nr_cisco_safekom(config-ext-nacl)#exit\r\nr_cisco_safekom(config)#crypto ipsec transform-set Phase2-SRX esp-sha-hmac esp-aes 256 \r\nr_cisco_safekom(cfg-crypto-trans)#exit\r\nr_cisco_safekom(config)#crypto map cryptomap01 10 ipsec-isakmp                             \r\nr_cisco_safekom(config-crypto-map)#set peer 192.168.1.2\r\nr_cisco_safekom(config-crypto-map)#set transform-set Phase2-SRX\r\nr_cisco_safekom(config-crypto-map)#match address VPN-SRX\r\nr_cisco_safekom(config-crypto-map)#set security-association lifetime seconds 3600\r\nr_cisco_safekom(config-crypto-map)#set pfs group2     \r\nr_cisco_safekom(config-crypto-map)#exit<\/pre>\n<p>przypi\u0119cie kryptomapy do interfejsu &#8222;publicznego&#8221;<\/p>\n<pre class=\"lang:sh decode:true\">r_cisco_safekom(config)#interface GigabitEthernet0\/1\r\nr_cisco_safekom(config-if)#crypto map cryptomap01\r\nr_cisco_safekom(config-if)#exit\r\nr_cisco_safekom(config)#exit<\/pre>\n<h3>Konfiguracja Juniper<\/h3>\n<p>Logujemy si\u0119 na urz\u0105dzenie:<\/p>\n<pre class=\"lang:sh decode:true \">--- JUNOS 12.1X46-D35.1 built 2015-05-14 23:19:08 UTC\r\n \r\nroot@srx_lab% \r\nroot@srx_lab% cli\r\nroot@srx_lab&gt; configure \r\nEntering configuration mode\r\n\r\n[edit]\r\nroot@srx_lab#<\/pre>\n<p>w\u0142\u0105czenie IKE na interfejsie &#8222;publicznym&#8221; w mym przypadku b\u0119dzie to fe-0\/0\/7.0 kt\u00f3ry nale\u017cy do zony untrust<\/p>\n<pre class=\"lang:sh decode:true\">set security zones security-zone untrust interfaces fe-0\/0\/7.0 host-inbound-traffic system-services ike<\/pre>\n<p>Konfiguracja fazy 1<\/p>\n<pre class=\"lang:sh decode:true \">set security ike proposal IKE-phase1-LAB01 authentication-method pre-shared-keys\r\nset security ike proposal IKE-phase1-LAB01 dh-group group2\r\nset security ike proposal IKE-phase1-LAB01 authentication-algorithm sha1\r\nset security ike proposal IKE-phase1-LAB01 encryption-algorithm aes-256-cbc\r\nset security ike proposal IKE-phase1-LAB01 lifetime-seconds 3600\r\nset security ike policy ike-phase1-LAB01 mode main\r\nset security ike policy ike-phase1-LAB01 proposals IKE-phase1-LAB01\r\nset security ike policy ike-phase1-LAB01 pre-shared-key ascii-text Qwert67890!  \r\nset security ike gateway gw-Cisco-lab ike-policy ike-phase1-LAB01\r\nset security ike gateway gw-Cisco-lab address 192.168.1.201\r\nset security ike gateway gw-Cisco-lab external-interface fe-0\/0\/7\r\nset security ike gateway gw-Cisco-lab local-address 192.168.1.2<\/pre>\n<p>Konfiguracja fazy 2<\/p>\n<pre class=\"lang:sh decode:true \">set security ipsec proposal ipsec-phase2-lab01 protocol esp\r\nset security ipsec proposal ipsec-phase2-lab01 authentication-algorithm hmac-sha1-96\r\nset security ipsec proposal ipsec-phase2-lab01 encryption-algorithm aes-256-cbc\r\nset security ipsec policy ipsec-phase2-lab01-polcy perfect-forward-secrecy keys group2\r\nset security ipsec policy ipsec-phase2-lab01-polcy proposals ipsec-phase2-lab01\r\nset security ipsec vpn ike-vpn-cisco ike gateway gw-Cisco-lab\r\nset security ipsec vpn ike-vpn-cisco ike proxy-identity local 10.10.10.0\/24\r\nset security ipsec vpn ike-vpn-cisco ike proxy-identity remote 172.16.10.0\/24\r\nset security ipsec vpn ike-vpn-cisco ike proxy-identity service any\r\nset security ipsec vpn ike-vpn-cisco ike ipsec-policy ipsec-phase2-lab01-polcy\r\nset security ipsec vpn ike-vpn-cisco establish-tunnels immediately<\/pre>\n<p>Utworzenie wpis\u00f3w w adres booku, od wersji 11 jest dost\u0119pny globalny adress book kt\u00f3ry jest wygodniejszy.<\/p>\n<pre class=\"lang:sh decode:true \">set security address-book global address Cisco_LAN_172.16.10.0 172.16.10.0\/24\r\nset security address-book global address SRX_LAN_10.10.10.0 10.10.10.0\/24<\/pre>\n<p>polityka fw puszczaj\u0105ca ruch z trust do untrust do VPN<\/p>\n<pre class=\"lang:sh decode:true\">set security policies from-zone trust to-zone untrust policy vpn-tr-untr match source-address SRX_LAN_10.10.10.0\r\nset security policies from-zone trust to-zone untrust policy vpn-tr-untr match destination-address Cisco_LAN_172.16.10.0\r\nset security policies from-zone trust to-zone untrust policy vpn-tr-untr match application any\r\nset security policies from-zone trust to-zone untrust policy vpn-tr-untr then permit tunnel ipsec-vpn ike-vpn-cisco<\/pre>\n<p>polityka fw puszczaj\u0105ca ruch z untrust (VPN) \u00a0do trust<\/p>\n<pre class=\"lang:sh decode:true\">set security policies from-zone untrust to-zone trust policy vpn-untr-tr match source-address Cisco_LAN_172.16.10.0\r\nset security policies from-zone untrust to-zone trust policy vpn-untr-tr match destination-address SRX_LAN_10.10.10.0\r\nset security policies from-zone untrust to-zone trust policy vpn-untr-tr match application any\r\nset security policies from-zone untrust to-zone trust policy vpn-untr-tr then permit tunnel ipsec-vpn ike-vpn-cisco<\/pre>\n<p>przsuwamy polityk\u0119 tak aby polityka any from trust to untrust nie przykrywa\u0142a polityki na ruch vpn<\/p>\n<pre class=\"lang:sh decode:true \">edit security policies from-zone trust to-zone untrust\r\ninsert policy vpn-tr-untr before policy trust-to-untrust<\/pre>\n<h3>Sprawdzenie<\/h3>\n<p>Sprawdzenie fazy 1 na SRX&#8217;e<\/p>\n<pre class=\"lang:sh decode:true \">root@srx_lab&gt; show security ike security-associations detail    \r\nIKE peer 192.168.1.201, Index 2255662, Gateway Name: gw-Cisco-lab\r\n  Role: Initiator, State: UP\r\n  Initiator cookie: 0b89dcdf6361b9e9, Responder cookie: 304cf2052afd6dd1\r\n  Exchange type: Main, Authentication method: Pre-shared-keys\r\n  Local: 192.168.1.2:500, Remote: 192.168.1.201:500\r\n  Lifetime: Expires in 3349 seconds\r\n  Peer ike-id: 192.168.1.201\r\n  Xauth assigned IP: 0.0.0.0\r\n  Algorithms:\r\n   Authentication        : hmac-sha1-96 \r\n   Encryption            : aes256-cbc\r\n   Pseudo random function: hmac-sha1\r\n   Diffie-Hellman group  : DH-group-2\r\n  Traffic statistics:\r\n   Input  bytes  :                  816\r\n   Output bytes  :                 1256\r\n   Input  packets:                    4\r\n   Output packets:                    6\r\n  Flags: IKE SA is created \r\n  IPSec security associations: 1 created, 0 deleted\r\n  Phase 2 negotiations in progress: 0\r\n\r\n    Negotiation type: Quick mode, Role: Initiator, Message ID: 0\r\n    Local: 192.168.1.2:500, Remote: 192.168.1.201:500\r\n    Local identity: 192.168.1.2\r\n    Remote identity: 192.168.1.201\r\n    Flags: IKE SA is created<\/pre>\n<p>Sprawdzenie fazy 1 na Cisco<\/p>\n<pre class=\"lang:sh decode:true \">r_cisco_safekom#show crypto isakmp sa \r\nIPv4 Crypto ISAKMP SA\r\ndst             src             state          conn-id status\r\n192.168.1.201   192.168.1.2     QM_IDLE           1001 ACTIVE<\/pre>\n<p>Sprawdzenie komunikacji na Cisco<\/p>\n<pre class=\"lang:sh decode:true \">r_cisco_safekom#ping 10.10.10.1 source 172.16.10.1\r\nType escape sequence to abort.\r\nSending 5, 100-byte ICMP Echos to 10.10.10.1, timeout is 2 seconds:\r\nPacket sent with a source address of 172.16.10.1 \r\n!!!!!\r\nSuccess rate is 100 percent (5\/5), round-trip min\/avg\/max = 1\/2\/4 ms<\/pre>\n<p>sprawdzenie komunikacji z pc kt\u00f3ry jest pod\u0142\u0105czony do SRX w sieci 10.10.10.0\/24<\/p>\n<pre class=\"lang:sh decode:true \">C:\\Users\\admin&gt;ping 172.16.10.1\r\n\r\nBadanie 172.16.10.1 z 32 bajtami danych:\r\nOdpowied\u017a z 172.16.10.1: bajt\u00f3w=32 czas=2ms TTL=254\r\nOdpowied\u017a z 172.16.10.1: bajt\u00f3w=32 czas=2ms TTL=254\r\n\r\nStatystyka badania ping dla 172.16.10.1:\r\n    Pakiety: Wys\u0142ane = 2, Odebrane = 2, Utracone = 0\r\n             (0% straty),\r\nSzacunkowy czas b\u0142\u0105dzenia pakiet\u00f3w w millisekundach:\r\n    Minimum = 2 ms, Maksimum = 2 ms, Czas \u015bredni = 2 ms\r\nControl-C\r\n^C<\/pre>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Dzi\u015b postanowi\u0142em opisa\u0107 troch\u0119 labowania, temat ostatnio bardzo mocno przerabiany IPSEC. Poni\u017cej opisz\u0119 wariant policy base vpn, kt\u00f3ry jest bardzo elastyczny. Za\u0142o\u017cenia: Faza 1 aes256 sha-1 pfs g2 3600s Faza 2 aes256 sha-1 pfs g2 3600s Cisco Juniper SRX Sieci kt\u00f3re b\u0119d\u0105 podlega\u0142y szyfrowaniu 172.16.10.0\/24 10.10.10.0\/24 Cisco Juniper SRX Interfejs z adresem tzw. publicznym 192.168.1.201\/24 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":269,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[4,5],"tags":[13,77,70,73,30],"class_list":["post-171","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cisco","category-juniper","tag-cisco","tag-ipsec","tag-juniper","tag-junos","tag-vpn"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Lab - IPSEC Juniper SRX - Cisco router - SafeKom Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ipsec-juniper-srx-cisco-router\/\" \/>\n<meta property=\"og:locale\" content=\"pl_PL\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Lab - IPSEC Juniper SRX - Cisco router - SafeKom Blog\" \/>\n<meta property=\"og:description\" content=\"Dzi\u015b postanowi\u0142em opisa\u0107 troch\u0119 labowania, temat ostatnio bardzo mocno przerabiany IPSEC. Poni\u017cej opisz\u0119 wariant policy base vpn, kt\u00f3ry jest bardzo elastyczny. Za\u0142o\u017cenia: Faza 1 aes256 sha-1 pfs g2 3600s Faza 2 aes256 sha-1 pfs g2 3600s Cisco Juniper SRX Sieci kt\u00f3re b\u0119d\u0105 podlega\u0142y szyfrowaniu 172.16.10.0\/24 10.10.10.0\/24 Cisco Juniper SRX Interfejs z adresem tzw. publicznym 192.168.1.201\/24 [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ipsec-juniper-srx-cisco-router\/\" \/>\n<meta property=\"og:site_name\" content=\"SafeKom Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/safekompl\" \/>\n<meta property=\"article:published_time\" content=\"2015-08-21T08:18:09+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2015-08-21T08:18:28+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/junos_multicolor_burst.png?fit=361%2C393&ssl=1\" \/>\n\t<meta property=\"og:image:width\" content=\"361\" \/>\n\t<meta property=\"og:image:height\" content=\"393\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Micha\u0142 Iwa\u0144czuk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@MIwaczuk\" \/>\n<meta name=\"twitter:site\" content=\"@MIwaczuk\" \/>\n<meta name=\"twitter:label1\" content=\"Napisane przez\" \/>\n\t<meta name=\"twitter:data1\" content=\"Micha\u0142 Iwa\u0144czuk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Szacowany czas czytania\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minut\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ipsec-juniper-srx-cisco-router\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ipsec-juniper-srx-cisco-router\\\/\"},\"author\":{\"name\":\"Micha\u0142 Iwa\u0144czuk\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#\\\/schema\\\/person\\\/fd4cc931b624af4b7353d36d92ba7181\"},\"headline\":\"Lab &#8211; IPSEC Juniper SRX &#8211; Cisco router\",\"datePublished\":\"2015-08-21T08:18:09+00:00\",\"dateModified\":\"2015-08-21T08:18:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ipsec-juniper-srx-cisco-router\\\/\"},\"wordCount\":197,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ipsec-juniper-srx-cisco-router\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2015\\\/08\\\/junos_multicolor_burst.png?fit=361%2C393&ssl=1\",\"keywords\":[\"cisco\",\"ipsec\",\"Juniper\",\"Junos\",\"vpn\"],\"articleSection\":[\"Cisco\",\"Juniper\"],\"inLanguage\":\"pl-PL\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ipsec-juniper-srx-cisco-router\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ipsec-juniper-srx-cisco-router\\\/\",\"url\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ipsec-juniper-srx-cisco-router\\\/\",\"name\":\"Lab - IPSEC Juniper SRX - Cisco router - SafeKom Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ipsec-juniper-srx-cisco-router\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ipsec-juniper-srx-cisco-router\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2015\\\/08\\\/junos_multicolor_burst.png?fit=361%2C393&ssl=1\",\"datePublished\":\"2015-08-21T08:18:09+00:00\",\"dateModified\":\"2015-08-21T08:18:28+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ipsec-juniper-srx-cisco-router\\\/#breadcrumb\"},\"inLanguage\":\"pl-PL\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ipsec-juniper-srx-cisco-router\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"pl-PL\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ipsec-juniper-srx-cisco-router\\\/#primaryimage\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2015\\\/08\\\/junos_multicolor_burst.png?fit=361%2C393&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2015\\\/08\\\/junos_multicolor_burst.png?fit=361%2C393&ssl=1\",\"width\":361,\"height\":393},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/cisco\\\/lab-ipsec-juniper-srx-cisco-router\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Strona g\u0142\u00f3wna\",\"item\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Lab &#8211; IPSEC Juniper SRX &#8211; Cisco router\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/\",\"name\":\"SafeKom Blog\",\"description\":\"Notatki Architekta i in\u017cyniera zwi\u0105zanego rozwi\u0105zaniami on-prem\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"pl-PL\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#organization\",\"name\":\"SafeKom Blog\",\"url\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pl-PL\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2015\\\/05\\\/cropped-logo.png?fit=512%2C512&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/www.safekom.pl\\\/blog\\\/wp-content\\\/uploads\\\/2015\\\/05\\\/cropped-logo.png?fit=512%2C512&ssl=1\",\"width\":512,\"height\":512,\"caption\":\"SafeKom Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/safekompl\",\"https:\\\/\\\/x.com\\\/MIwaczuk\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/michaliwanczuk\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/#\\\/schema\\\/person\\\/fd4cc931b624af4b7353d36d92ba7181\",\"name\":\"Micha\u0142 Iwa\u0144czuk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pl-PL\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g\",\"caption\":\"Micha\u0142 Iwa\u0144czuk\"},\"description\":\"Pasjonat komputerowy od zawsze oraz maniak w zakresie sieci, wirtualizacji oraz bezpiecze\u0144stwa IT. Kompetentny in\u017cynier z du\u017cym do\u015bwiadczeniem w realizacji projekt\u00f3w informatycznych i telekomunikacyjnych. Wieloletni administrator IT, kt\u00f3ry utrzymuje systemy informatyczne dostosowuj\u0105c je do wymog\u00f3w biznesowych z zapewnieniem dost\u0119pno\u015bci 24\\\/7\\\/365.\",\"url\":\"https:\\\/\\\/www.safekom.pl\\\/blog\\\/author\\\/admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Lab - IPSEC Juniper SRX - Cisco router - SafeKom Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ipsec-juniper-srx-cisco-router\/","og_locale":"pl_PL","og_type":"article","og_title":"Lab - IPSEC Juniper SRX - Cisco router - SafeKom Blog","og_description":"Dzi\u015b postanowi\u0142em opisa\u0107 troch\u0119 labowania, temat ostatnio bardzo mocno przerabiany IPSEC. Poni\u017cej opisz\u0119 wariant policy base vpn, kt\u00f3ry jest bardzo elastyczny. Za\u0142o\u017cenia: Faza 1 aes256 sha-1 pfs g2 3600s Faza 2 aes256 sha-1 pfs g2 3600s Cisco Juniper SRX Sieci kt\u00f3re b\u0119d\u0105 podlega\u0142y szyfrowaniu 172.16.10.0\/24 10.10.10.0\/24 Cisco Juniper SRX Interfejs z adresem tzw. publicznym 192.168.1.201\/24 [&hellip;]","og_url":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ipsec-juniper-srx-cisco-router\/","og_site_name":"SafeKom Blog","article_publisher":"https:\/\/www.facebook.com\/safekompl","article_published_time":"2015-08-21T08:18:09+00:00","article_modified_time":"2015-08-21T08:18:28+00:00","og_image":[{"width":361,"height":393,"url":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/junos_multicolor_burst.png?fit=361%2C393&ssl=1","type":"image\/png"}],"author":"Micha\u0142 Iwa\u0144czuk","twitter_card":"summary_large_image","twitter_creator":"@MIwaczuk","twitter_site":"@MIwaczuk","twitter_misc":{"Napisane przez":"Micha\u0142 Iwa\u0144czuk","Szacowany czas czytania":"5 minut"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ipsec-juniper-srx-cisco-router\/#article","isPartOf":{"@id":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ipsec-juniper-srx-cisco-router\/"},"author":{"name":"Micha\u0142 Iwa\u0144czuk","@id":"https:\/\/www.safekom.pl\/blog\/#\/schema\/person\/fd4cc931b624af4b7353d36d92ba7181"},"headline":"Lab &#8211; IPSEC Juniper SRX &#8211; Cisco router","datePublished":"2015-08-21T08:18:09+00:00","dateModified":"2015-08-21T08:18:28+00:00","mainEntityOfPage":{"@id":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ipsec-juniper-srx-cisco-router\/"},"wordCount":197,"commentCount":0,"publisher":{"@id":"https:\/\/www.safekom.pl\/blog\/#organization"},"image":{"@id":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ipsec-juniper-srx-cisco-router\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/junos_multicolor_burst.png?fit=361%2C393&ssl=1","keywords":["cisco","ipsec","Juniper","Junos","vpn"],"articleSection":["Cisco","Juniper"],"inLanguage":"pl-PL","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.safekom.pl\/blog\/cisco\/lab-ipsec-juniper-srx-cisco-router\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ipsec-juniper-srx-cisco-router\/","url":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ipsec-juniper-srx-cisco-router\/","name":"Lab - IPSEC Juniper SRX - Cisco router - SafeKom Blog","isPartOf":{"@id":"https:\/\/www.safekom.pl\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ipsec-juniper-srx-cisco-router\/#primaryimage"},"image":{"@id":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ipsec-juniper-srx-cisco-router\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/junos_multicolor_burst.png?fit=361%2C393&ssl=1","datePublished":"2015-08-21T08:18:09+00:00","dateModified":"2015-08-21T08:18:28+00:00","breadcrumb":{"@id":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ipsec-juniper-srx-cisco-router\/#breadcrumb"},"inLanguage":"pl-PL","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.safekom.pl\/blog\/cisco\/lab-ipsec-juniper-srx-cisco-router\/"]}]},{"@type":"ImageObject","inLanguage":"pl-PL","@id":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ipsec-juniper-srx-cisco-router\/#primaryimage","url":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/junos_multicolor_burst.png?fit=361%2C393&ssl=1","contentUrl":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/junos_multicolor_burst.png?fit=361%2C393&ssl=1","width":361,"height":393},{"@type":"BreadcrumbList","@id":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-ipsec-juniper-srx-cisco-router\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Strona g\u0142\u00f3wna","item":"https:\/\/www.safekom.pl\/blog\/"},{"@type":"ListItem","position":2,"name":"Lab &#8211; IPSEC Juniper SRX &#8211; Cisco router"}]},{"@type":"WebSite","@id":"https:\/\/www.safekom.pl\/blog\/#website","url":"https:\/\/www.safekom.pl\/blog\/","name":"SafeKom Blog","description":"Notatki Architekta i in\u017cyniera zwi\u0105zanego rozwi\u0105zaniami on-prem","publisher":{"@id":"https:\/\/www.safekom.pl\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.safekom.pl\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"pl-PL"},{"@type":"Organization","@id":"https:\/\/www.safekom.pl\/blog\/#organization","name":"SafeKom Blog","url":"https:\/\/www.safekom.pl\/blog\/","logo":{"@type":"ImageObject","inLanguage":"pl-PL","@id":"https:\/\/www.safekom.pl\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/05\/cropped-logo.png?fit=512%2C512&ssl=1","contentUrl":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/05\/cropped-logo.png?fit=512%2C512&ssl=1","width":512,"height":512,"caption":"SafeKom Blog"},"image":{"@id":"https:\/\/www.safekom.pl\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/safekompl","https:\/\/x.com\/MIwaczuk","https:\/\/www.linkedin.com\/in\/michaliwanczuk\/"]},{"@type":"Person","@id":"https:\/\/www.safekom.pl\/blog\/#\/schema\/person\/fd4cc931b624af4b7353d36d92ba7181","name":"Micha\u0142 Iwa\u0144czuk","image":{"@type":"ImageObject","inLanguage":"pl-PL","@id":"https:\/\/secure.gravatar.com\/avatar\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/cc6dda4ee8d21d1f254147e5ee6f5e38881b88a4a12a5774ca42380597e52014?s=96&d=mm&r=g","caption":"Micha\u0142 Iwa\u0144czuk"},"description":"Pasjonat komputerowy od zawsze oraz maniak w zakresie sieci, wirtualizacji oraz bezpiecze\u0144stwa IT. Kompetentny in\u017cynier z du\u017cym do\u015bwiadczeniem w realizacji projekt\u00f3w informatycznych i telekomunikacyjnych. Wieloletni administrator IT, kt\u00f3ry utrzymuje systemy informatyczne dostosowuj\u0105c je do wymog\u00f3w biznesowych z zapewnieniem dost\u0119pno\u015bci 24\/7\/365.","url":"https:\/\/www.safekom.pl\/blog\/author\/admin\/"}]}},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/junos_multicolor_burst.png?fit=361%2C393&ssl=1","jetpack_shortlink":"https:\/\/wp.me\/p7i9ri-2L","jetpack-related-posts":[{"id":292,"url":"https:\/\/www.safekom.pl\/blog\/juniper\/lab-ipsec-srx-palo\/","url_meta":{"origin":171,"position":0},"title":"LAB &#8211; IPSEC SRX  PALO","author":"Micha\u0142 Iwa\u0144czuk","date":"30.08.2015","format":false,"excerpt":"Dzi\u015b przyszed\u0142 czas na lab z wykorzystaniem urz\u0105dze\u0144 Juniper SRX oraz Palo Alto Networks. Skupi\u0119 si\u0119 w tym wpisie na skonfigurowaniu po\u0142\u0105czenia VPN Ipsec pomi\u0119dzy tymi urz\u0105dzeniami. za\u0142o\u017cenia: Faza 1 aes256 sha-1 pfs g2 3600s Faza 2 aes256 sha-1 pfs g2 3600s Palo SRX Sieci kt\u00f3re b\u0119d\u0105 podlega\u0142y szyfrowaniu 10.20.10.0\/24\u2026","rel":"","context":"W \u201eJuniper&quot;","block_context":{"text":"Juniper","link":"https:\/\/www.safekom.pl\/blog\/category\/juniper\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1&resize=525%2C300 1.5x"},"classes":[]},{"id":647,"url":"https:\/\/www.safekom.pl\/blog\/lab\/lab_ipsec_palo_ciscoasa\/","url_meta":{"origin":171,"position":1},"title":"LAB &#8211;  IPSec Palo &#8211; Cisco ASA","author":"Micha\u0142 Iwa\u0144czuk","date":"23.03.2016","format":false,"excerpt":"Poni\u017cej pokazuj\u0119 jak zestawia\u0107 po\u0142\u0105czenie IPsec pomi\u0119dzy PaloAlto Networks a Cisco ASA. W mym przypadku oba urz\u0105dzenia s\u0105 w wersji wirtualnej ale konfiguracja ich odpowiada tak jak by\u015bmy konfigurowali urz\u0105dzenia fizyczne. Za\u0142o\u017cenia: Faza 1 aes256 sha-1 pfs g2 86400s Faza 2 aes256 sha-1 pfs g2 28800s Palo Cisco ASA Sieci\u2026","rel":"","context":"W \u201eCisco&quot;","block_context":{"text":"Cisco","link":"https:\/\/www.safekom.pl\/blog\/category\/cisco\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2015\/08\/Paloalto_logo.png?fit=566%2C680&ssl=1&resize=525%2C300 1.5x"},"classes":[]},{"id":465,"url":"https:\/\/www.safekom.pl\/blog\/juniper\/juniper-ograniczenie-dostepu-do-ike\/","url_meta":{"origin":171,"position":2},"title":"Juniper &#8211; Ograniczenie dost\u0119pu do IKE","author":"Micha\u0142 Iwa\u0144czuk","date":"30.12.2015","format":false,"excerpt":"Co zrobi\u0107 aby na urz\u0105dzeniu na kt\u00f3rym jest uruchomiona us\u0142uga IKE na skanach bezpiecze\u0144stwa nie pojawia\u0142o si\u0119 \u017ce jest w\u0142\u0105czony aggressive mode. Najszybciej b\u0119dzie za\u0142o\u017cenie filtru kt\u00f3ry b\u0119dzie nam dopuszcza\u0142 wybrane adresy peer\u00f3w do us\u0142ugi IKE i ESP Definiujemy grup\u0119 w kt\u00f3rej b\u0119dzie lista adres\u00f3w IP i sieci kt\u00f3re b\u0119d\u0105\u2026","rel":"","context":"W \u201eJuniper&quot;","block_context":{"text":"Juniper","link":"https:\/\/www.safekom.pl\/blog\/category\/juniper\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":2567,"url":"https:\/\/www.safekom.pl\/blog\/vmware\/nsx\/nsx-t-ipsec-route-base\/","url_meta":{"origin":171,"position":3},"title":"NSX-t IPSec Route base","author":"Micha\u0142 Iwa\u0144czuk","date":"26.03.2020","format":false,"excerpt":"W dzisiejszym wpisie przedstawi\u0119 konfiguracj\u0119 NSX-t IPSec Route base, jest to\u00a0 opis krok po kroku jak skonfigurowa\u0107 IPseca po stronie NSX'a oraz Vyos kt\u00f3ry b\u0119dzie uczestnikiem IPseca.\u00a0 Za\u0142o\u017cenia Poni\u017cej rysunek pogl\u0105dowy jak wygl\u0105da topologia po\u0142\u0105cze\u0144. Pomi\u0119dzy routerem T0 i chmurk\u0105 ju\u017c istnieje po\u0142\u0105czenie oraz jest zestawione s\u0105siedztwo BGP w celu\u2026","rel":"","context":"W \u201eNSX&quot;","block_context":{"text":"NSX","link":"https:\/\/www.safekom.pl\/blog\/category\/vmware\/nsx\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2018\/01\/Autobot_symbol.png?fit=1012%2C946&ssl=1&resize=700%2C400 2x"},"classes":[]},{"id":908,"url":"https:\/\/www.safekom.pl\/blog\/vmware\/home-lab-wstep\/","url_meta":{"origin":171,"position":4},"title":"Home Lab &#8211; wst\u0119p","author":"Micha\u0142 Iwa\u0144czuk","date":"10.06.2016","format":false,"excerpt":"Przyszed\u0142 dzie\u0144, w kt\u00f3rym trzeba sko\u0144czy\u0107 budowa\u0107 m\u00f3j domowy lab. W tej chwili mocno na tapecie mam NSX oraz VxLAN. Na mym laptopie ju\u017c wi\u0119cej nie upcham wirtualnych maszyn, przyszed\u0142 czas na z\u0142o\u017cenie porz\u0105dnego Laba. Tym wpisem rozpoczn\u0119 seri\u0119 od budowania po testowanie rozwi\u0105za\u0144 Vmware. Sprz\u0119t do Laba: Serwer fizyczny:\u2026","rel":"","context":"W \u201eLab&quot;","block_context":{"text":"Lab","link":"https:\/\/www.safekom.pl\/blog\/en\/category\/lab\/"},"img":{"alt_text":"home_lab01","src":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/06\/home_lab01.png?resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/06\/home_lab01.png?resize=350%2C200 1x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/06\/home_lab01.png?resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/06\/home_lab01.png?resize=700%2C400 2x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/06\/home_lab01.png?resize=1050%2C600 3x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/06\/home_lab01.png?resize=1400%2C800 4x"},"classes":[]},{"id":782,"url":"https:\/\/www.safekom.pl\/blog\/cisco\/lab-vxlan-juniper-vmx-i-cisco-csr1kv-asav\/","url_meta":{"origin":171,"position":5},"title":"LAB vxlan &#8211; Juniper vMX i Cisco CSR1kv oraz ASAv","author":"Micha\u0142 Iwa\u0144czuk","date":"26.04.2016","format":false,"excerpt":"Po pierwszym wpisie o VxLAN, gdzie opar\u0142em si\u0119 wy\u0142\u0105cznie na Cisco CSRv oraz ASAv przysz\u0142a pora na testowanie w konfiguracji multivendor. Do tego laba wykorzysta\u0142em: Cisco CSRv Cisco ASAv Juniper vMX Wszystko zosta\u0142o uruchomione na Vmware Workstation. W dobie wirtualizacji serwer\u00f3w i desktop\u00f3w postanowi\u0142em wzi\u0105\u0107 si\u0119 ostro za poznanie \u015bwiata\u2026","rel":"","context":"W \u201eCisco&quot;","block_context":{"text":"Cisco","link":"https:\/\/www.safekom.pl\/blog\/category\/cisco\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/02\/Juniper-Networks-and-Cisco-Systems.png?fit=712%2C534&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/02\/Juniper-Networks-and-Cisco-Systems.png?fit=712%2C534&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/02\/Juniper-Networks-and-Cisco-Systems.png?fit=712%2C534&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.safekom.pl\/blog\/wp-content\/uploads\/2016\/02\/Juniper-Networks-and-Cisco-Systems.png?fit=712%2C534&ssl=1&resize=700%2C400 2x"},"classes":[]}],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/posts\/171","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/comments?post=171"}],"version-history":[{"count":0,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/posts\/171\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/media\/269"}],"wp:attachment":[{"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/media?parent=171"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/categories?post=171"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.safekom.pl\/blog\/wp-json\/wp\/v2\/tags?post=171"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}