IPSec Configuration Example
581
[RouterA]
interface serial 0
l
Configure ip address of the serial interface
[RouterA-Serial0]
ip address 202.38.163.1 255.255.255.0
m
Apply security policy group on serial interface
[RouterA-Serial0]
ipsec policy policy1
n
Configure the route.
[RouterA]
ip route-static 10.1.2.0 255.255.255.0 202.38.162.1
o
Configure corresponding IKE
[RouterA]
ike pre-shared-key abcde remote 202.38.162.1
2
Configure Router B:
a
Configure an access list and define the data stream from Subnet 10.1.2x to
Subnet 10.1.1x.
[RouterB]
acl 101
[RouterB-acl-101]
rule permit ip source 10.1.2.0 0.0.0.255
destination 10.1.1.0 0.0.0.255
[RouterB-acl-101]
rule deny ip source any destination any
b
Create the IPSec proposal view named trans1
[RouterB]
ipsec proposal tran1
c
Adopt tunnel mode as the message-encapsulating form
[RouterB-ipsec-proposal-tran1]
encapsulation-mode tunnel
d
Adopt ESP protocol as security protocol
[RouterB-ipsec-proposal-tran1]
transform esp-new
e
Select authentication algorithm and encryption algorithm
[RouterB-ipsec-proposal-tran1]
esp-new encryption-algorithm des
[RouterB-ipsec-proposal-tran1]
esp-new authentication-algorithm
sha1-hmac-96
f
Create a security policy with negotiation view as isakmp
[RouterB]
ipsec policy use1 10 isakmp
g
Quote access list
[RouterB-crypto-map-use1-10]
match address 101
h
Set remote address
[RouterB-ipsec-policy-policy1-10]
security acl 101
i
Quote IPSec proposal
[RouterB-ipsec-policy-policy1-10]
proposal tran1
j
Configure serial interface Serial0
[RouterB]
interface serial 0
[RouterB-Serial0]
ip address 202.38.162.1 255.255.255.0
k
Apply security policy group on serial interface
[RouterB-Serial0]
ipsec policy use1
l
Configure the route.
[RouterB]
ip route-static 10.1.1.0 255.255.255.0 202.38.163.1
Содержание 3036
Страница 1: ...http www 3com com 3Com Router Configuration Guide Published March 2004 Part No 10014299 ...
Страница 4: ...VPN 615 RELIABILITY 665 QOS 681 DIAL UP 721 ...
Страница 6: ...2 ABOUT THIS GUIDE ...
Страница 7: ...I GETTING STARTED Chapter 1 3Com Router Introduction Chapter 2 3Com Router User Interface ...
Страница 8: ...4 ...
Страница 16: ...12 CHAPTER 1 3COM ROUTER INTRODUCTION ...
Страница 34: ...30 ...
Страница 60: ...56 CHAPTER 3 SYSTEM MANAGEMENT ...
Страница 88: ...84 CHAPTER 5 CONFIGURING NETWORK MANAGEMENT RouterA interface ethernet 0 RouterA Ethernet0 rmon promiscuous ...
Страница 98: ...94 CHAPTER 6 DISPLAY AND DEBUGGING TOOLS ...
Страница 110: ...106 ...
Страница 114: ...110 CHAPTER 8 INTERFACE CONFIGURATION OVERVIEW ...
Страница 158: ...154 CHAPTER 10 CONFIGURING WAN INTERFACE ...
Страница 168: ...164 ...
Страница 188: ...184 CHAPTER 13 CONFIGURING PPPOE CLIENT ...
Страница 192: ...188 CHAPTER 14 CONFIGURING SLIP Router ip route static 0 0 0 0 0 0 0 0 10 110 0 1 ...
Страница 248: ...244 CHAPTER 16 CONFIGURING LAPB AND X 25 ...
Страница 292: ...288 CHAPTER 18 CONFIGURING HDLC Enable HDLC packet debugging debugging hdlc packet interface type number ...
Страница 320: ...316 ...
Страница 330: ...326 CHAPTER 20 CONFIGURING IP ADDRESS ...
Страница 362: ...358 CHAPTER 21 CONFIGURING IP APPLICATION ...
Страница 374: ...370 CHAPTER 23 CONFIGURING IP COUNT ...
Страница 406: ...402 CHAPTER 25 CONFIGURING DLSW ...
Страница 408: ...404 ...
Страница 452: ...448 CHAPTER 29 CONFIGURING OSPF ...
Страница 482: ...478 CHAPTER 30 CONFIGURING BGP ...
Страница 494: ...490 CHAPTER 31 CONFIGURING IP ROUTING POLICY ...
Страница 502: ...498 ...
Страница 508: ...504 CHAPTER 33 IP MULTICAST ...
Страница 514: ...510 CHAPTER 34 CONFIGURING IGMP ...
Страница 526: ...522 CHAPTER 36 CONFIGURING PIM SM ...
Страница 528: ...524 ...
Страница 532: ...528 CHAPTER 37 CONFIGURING TERMINAL ACCESS SECURITY ...
Страница 550: ...546 CHAPTER 38 CONFIGURING AAA AND RADIUS PROTOCOL ...
Страница 590: ...586 CHAPTER 40 CONFIGURING IPSEC ...
Страница 599: ...IX VPN Chapter 42 Configuring VPN Chapter 43 Configuring L2TP Chapter 44 Configuring GRE ...
Страница 600: ...596 ...
Страница 638: ...634 CHAPTER 43 CONFIGURING L2TP ...
Страница 649: ...X RELIABILITY Chapter 45 Configuring a Standby Center Chapter 46 Configuring VRRP ...
Страница 650: ...646 ...
Страница 666: ...662 ...
Страница 670: ...666 CHAPTER 47 QOS OVERVIEW ...
Страница 700: ...696 CHAPTER 49 CONGESTION MANAGEMENT ...
Страница 706: ...702 CHAPTER 50 CONGESTION AVOIDANCE ...
Страница 707: ...XII DIAL UP Chapter 51 Configuring DCC Chapter 52 Configuring Modem ...
Страница 708: ...704 ...
Страница 762: ...758 CHAPTER 52 CONFIGURING MODEM ...