![Alcatel-Lucent OmniAccess 700 Скачать руководство пользователя страница 779](http://html.mh-extra.com/html/alcatel-lucent/omniaccess-700/omniaccess-700_cli-configuration-manual_2891856779.webp)
IPsec VPN Configuration
Except on the first page, right running head:
Heading1 or Heading1NewPage text (automatic)
753
Alcatel-Lucent
Beta
Beta
CLI Configuration Guide
IP
SEC
C
ONFIGURATION
C
OMMANDS
This section details the commands used in configuring IPsec VPN.
T
O
C
ONFIGURE
THE
M
ATCH
-
LISTS
To get a concise and terse outlook on the methods to configure the match-lists,
please refer
“Common Classifiers”
chapter in this guide.
To specify the subnets, which need to communicate with each other, match-list
(access-list) needs to be configured. This match-list is called by the crypto map
command.
In the OA-700, a wide variety of match-lists can be defined. However, a well-
defined subset of match-lists can be used for IPsec tunnel (a match-list should not
have ‘any any’ option). The match-list should not contain multiple rules or another
nested match-list/list. A rule should not have the ‘port range’ or ‘interfaces’
keywords.
However, these constraints can be overcome by applying multiple crypto maps to
the same interface.
For Example:
match-list
m1
ip prefix
10.0.0.0/8
prefix
9.0.0.0/8
IP
SEC
C
ONFIGURATION
WITH
P
RESHARED
K
EY
The Preshared key is used to authenticate peers. This key is same on both the
IPsec gateways. It is denoted in the form of a key-string. The “
force
“ keyword
edits or modifies the IKE keys, which are already configured.
Note:
The IKE key is given by means of a key-string. Currently, the preshared key length is
restricted to 128 characters, and the minimum length is 8 characters.
E
XAMPLE
ALU(config)#crypto ike key top_secret1612 peer 10.10.1.2
ALU(config)#crypto ike key "!netsecret!" peer 202.54.30.100
Command (in CM)
Description
crypto ike key
<key-string>
[
vrf <name>
]
peer
<
peer-
address>
[
force
]
This command is used to configure a
preshared key.
no crypto ike key
<key-
string>
[
vrf <name>
]
peer
<
peer-address>
This ‘no’ command removes the
configured preshared key.
Содержание OmniAccess 700
Страница 38: ...Left running head Chapter name automatic 12 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 176: ...Left running head Chapter name automatic 150 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 224: ...Per VLAN Spanning Tree Left running head Chapter name automatic 198 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 258: ...Port Monitoring Left running head Chapter name automatic 232 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 260: ...Left running head Chapter name automatic 234 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 296: ...T1E1 Line Card Left running head Chapter name automatic 270 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 360: ...Point to Point Protocol Left running head Chapter name automatic 334 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 434: ...Left running head Chapter name automatic 408 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 462: ...Common Classifiers Left running head Chapter name automatic 436 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 464: ...Left running head Chapter name automatic 438 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 534: ...Border Gateway Protocol Left running head Chapter name automatic 508 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 638: ...Left running head Chapter name automatic 612 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 762: ...Filter and Firewall Left running head Chapter name automatic 736 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 890: ...Transparent Firewall Left running head Chapter name automatic 864 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 940: ...Left running head Chapter name automatic 914 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1000: ...Quality of Service Left running head Chapter name automatic 974 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1002: ...Left running head Chapter name automatic 976 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1044: ...DNS Domain Name Service Client Left running head Chapter name automatic 1018 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1046: ...Left running head Chapter name automatic 1020 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1058: ...Left running head Chapter name automatic 1032 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1074: ...Lifeline Left running head Chapter name automatic 1048 Beta Beta CLI Configuration Guide Alcatel Lucent line con 0 end ...
Страница 1076: ...Left running head Chapter name automatic 1050 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1118: ...Web Cache Server Left running head Chapter name automatic 1092 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1120: ...Left running head Chapter name automatic 2 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1140: ...QoS Values and Mnemonics Left running head Chapter name automatic 22 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1156: ...IPsec Interoperability of OA 700 Left running head Chapter name automatic 38 Beta Beta CLI Configuration Guide Alcatel Lucent ...