CHAPTER 25. IPSEC
266
© SAMSUNG Electronics Co., Ltd.
Remote
ident(ip/mask/port):(10.0.2.0/255.255.255.0/
any)
Peer Address is 172.16.0.2, PFS Group is disabled
outbound ESP sas
Spi: 0xa1f673aa
Transform: aes128(key length=128 bits), sha1
In use settings = {tunnel}
Bytes Processed 256
Hard lifetime in seconds 3290, Hard lifetime in
kilobytes
413695
Soft lifetime in seconds 3200, Soft lifetime in
kilobytes
37355
Joining Two Private Networks Example
The following example demonstrates how to form an IP security tunnel to join
two private networks: 10.0.1.0/24 and 10.0.2.0/24. The security requirements
are as follows:
Phase 1: 3DES with SHA1
Phase 2: IPSec ESP with AES(256-bit) and HMAC-SHA1
Figure 25.2 Tunnel Mode Between Two Security Gateways-Single Proposals
1.
Configure a WAN bundle of network type untrusted.
Router/configure/interface/bundle wan1# link t1 0/2/0
Router/configure/interface/bundle wan1# encapsulation ppp
Router/configure/interface/bundle wan1# ip address
172.16.0.1 24
Router/configure/interface/bundle wan1# crypto untrusted
Router/configure/interface/bundle wan1# exit
Router 1
Router 2
IPSec ESP
UNTRUSTED
TRUSTED
TRUSTED
Network
10.0.1.0/24
Network
10.0.2.0/24
172.16.0.1
172.16.0.2
Summary of Contents for Ubigate iBG3026
Page 1: ......
Page 16: ...INTRODUCTION XIV SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 32: ...TABLE OF CONTENTS XXX SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 34: ......
Page 64: ...CHAPTER 4 System Logging 30 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 72: ......
Page 94: ...CHAPTER 7 WAN Interfaces 58 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 110: ......
Page 156: ...CHAPTER 15 BGP 118 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 178: ...CHAPTER 17 VRRP 140 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 262: ......
Page 288: ...CHAPTER 23 Firewall NAT 248 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 346: ......
Page 706: ...CHAPTER 36 Management 664 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 718: ...EQBD 000026 Ed 00 ...