MDS 05-6632A01, Rev. F
MDS Orbit MCR/ECR Technical Manual
339
Above NETMON configuration assumes AP’s bridge interface IP address is 192.168.1.4.
NOTE
Since the AP and REMOTEs are now part of a single layer-2 network, the bridge interfaces
need to be assigned distinct IP addresses.
Using the CLI
Configurable IPsec tunnel (a pre-shared-key based example shown below) from REMOTE to AP. It is
assumed that REMOTE-1’s cell IP address is 10.150.1.10, REMOTE-2’s cell IP address is 10.150.1.20
and AP’s cell IP address is 10.150.1.1.
AP Configuration
Configure IPsec transport mode connections
% set services vpn enabled
true
% set services vpn ike policy
REMOTE-1_ike_policy
auth-method
pre-shared-key
% set services vpn ike policy
REMOTE-1_ike_policy
pre-shared-key
remote1
% set services vpn ike policy
REMOTE-1_ike_policy
ciphersuite
ike_policy_cipher0
% set services vpn ike policy
REMOTE-1_ike_policy
life-time
180
% set services vpn ike peer
REMOTE-1_ike_peer
ike-policy
REMOTE-1_ike_policy
% set services vpn ike peer
REMOTE-1_ike_peer
local-endpoint address
10.150.1.1
% set services vpn ike peer
REMOTE-1_ike_peer
local-identity default
% set services vpn ike peer
REMOTE-1_ike_peer
peer-endpoint address
10.150.1.10
% set services vpn ike peer
REMOTE-1_ike_peer
peer-identity default
% set services vpn ike peer
REMOTE-2_ike_peer
role
responder
% set services vpn ipsec policy
REMOTE-1_ipsec_policy
ciphersuite
ipsec_policy_cipher0
% set services vpn ipsec policy
REMOTE-1_ipsec_policy
life-time
60
% set services vpn ipsec connection
REMOTE-1
ike-peer
REMOTE-1_ike_peer
% set services vpn ipsec connection
REMOTE-1
ipsec-policy
REMOTE-1_ipsec_policy
% set services vpn ipsec connection
REMOTE-1
host-to-host
% set services vpn ipsec connection
REMOTE-1
filter input
IN_TRUSTED
% set services vpn ipsec connection
REMOTE-1
filter output
OUT_TRUSTED
% set services vpn ike policy
REMOTE-2_ike_policy
auth-method
pre-shared-key
% set services vpn ike policy
REMOTE-2_ike_policy
pre-shared-key
remote2
% set services vpn ike policy
REMOTE-2_ike_policy
ciphersuite
ike_policy_cipher0
% set services vpn ike policy
REMOTE-2_ike_policy
life-time
180
% set services vpn ike peer
REMOTE-2_ike_peer
ike-policy
REMOTE-2_ike_policy
% set services vpn ike peer
REMOTE-2_ike_peer
local-endpoint address
10.150.1.1
% set services vpn ike peer
REMOTE-2_ike_peer
local-identity default
% set services vpn ike peer
REMOTE-2_ike_peer
peer-endpoint address
10.150.1.20
Summary of Contents for MDS ORBIT ECR
Page 15: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 15 ...
Page 35: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 35 ...
Page 145: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 145 ...
Page 188: ...188 MDS Orbit MCR ECR Technical Manual MDS 05 6632A01 Rev F ...
Page 302: ...302 MDS Orbit MCR ECR Technical Manual MDS 05 6632A01 Rev F Figure 3 224 SNMP Main Page ...
Page 380: ...380 MDS Orbit MCR ECR Technical Manual MDS 05 6632A01 Rev F ...
Page 389: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 389 ...
Page 393: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 393 ...
Page 407: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 407 ...
Page 449: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 449 ...
Page 451: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 451 ...
Page 452: ...452 MDS Orbit MCR ECR Technical Manual MDS 05 6632A01 Rev F ...
Page 453: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 453 ...
Page 459: ...MDS 05 6632A01 Rev F MDS Orbit MCR ECR Technical Manual 459 NOTES ...
Page 460: ...460 MDS Orbit MCR ECR Technical Manual MDS 05 6632A01 Rev F ...
Page 461: ......