data:image/s3,"s3://crabby-images/2b270/2b27073b360580044f754107af70fdddcd715c75" alt="Arista vEOS Скачать руководство пользователя страница 105"
Encryption - AES256
•
• Integrity - SHA256
• DH group - Group 14
• IKE lifetime - 8 hours
Example:
veos(config-ipsec)#ike policy ike-vrouter
veos(config-ipsec-ike)#encryption aes256
veos(config-ipsec-ike)#integrity sha256
veos(config-ipsec-ike)#dh-group 24
veos(config-ipsec-ike)#version 2
veos(config-ipsec-ike)#exit
veos(config-ipsec)#ike policy ike-default
veos(config-ipsec-ike)#version 2
veos(config-ipsec-ike)#exit
3. If the router is behind a NAT, configure the local-id with the local public IP address.
Example:
veos(config-ipsec-ike)#local-id <public ip address>
4. Create an IPsec Security Association policy used in the data path for encryption and integrity. The is an
option of enabling Perfect Forward Secrecy by configuring a DH group to the SA.
Example: In this example, AES256 is used for encryption, SHA 256 is used for integrity, and Perfect
Forward Secrecy is enabled (the DH group is 14).
veos(config-ipsec)#sa policy sa-vrouter
veos(config-ipsec-sa)#esp encryption aes256
veos(config-ipsec-sa)#esp integrity sha256
veos(config-ipsec-sa)#pfs dh-group 14
veos(config-ipsec-sa)#sa lifetime 2
veos(config-ipsec-sa)#exit
veos(config-ipsec)#sa policy sa-default
veos(config-ipsec-sa)#exit
5. Bind or associate the IKE and SA policies together using a IPsec profile. Provide a shared-key, which must
be common on both peers. The default profile assigns default values for all parameters that are not explicitly
configured in the other profiles.
Example: In this example, tunnel mode is set to transport. The IKE Policy ike-peerRtr and SA Policy
sa-peerRtr are applied to profile peer-Rtr. Dead Peer Detection is enabled and configured to delete the
connection when the peer is down for more than 50 seconds. The peer (peer-Rtr) is set to be the responder.
veos(config-ipsec)#profile default
veos(config-ipsec-profile)#ike-policy ikedefault
veos(config-ipsec-profile)#sa-policy sadefault
veos(config-ipsec-profile)#shared-key arista
veos(config-ipsec)#profile peer-Rtr
veos(config-ipsec-profile)#ike-policy ike-peerRtr
veos(config-ipsec-profile)#sa-policy sa-peerRtr
veos(config-ipsec-profile)#dpd 10 50 clear
veos(config-ipsec-profile)#connection add
veos(config-ipsec-profile)#mode transport
6. Configure the WAN interface to be the underlying interface for the tunnel. Specify an L3 address for the
tunnel. If the L3 address is not specified, the vEOS Router cannot route packets using the tunnel.
105
IPsec Support
Содержание vEOS
Страница 6: ......
Страница 12: ......
Страница 60: ......
Страница 72: ......
Страница 77: ...7 Select the default network 8 Complete the launch process 77 Server Requirements ...
Страница 94: ...Figure 17 Linux SRIOV PCI Passthrough based Deployment vEOS Router Configuration Guide 94 ...
Страница 124: ......
Страница 128: ......