data:image/s3,"s3://crabby-images/cf802/cf8026a3a6b129e71c6b709b6827bcf0e031ec28" alt="Arista vEOS Скачать руководство пользователя страница 106"
Example:
veos(config)#interface Et1
veos(config-if-Et1)#no switchport
veos(config-if-Et1)#ip address 1.0.0.1/24
veos(config-if-Et1)#mtu 1500
7. Apply the IPsec profile to a new tunnel interface. Create the new tunnel interface as part of this step.
Example: In this example, the new tunnel interface is Tunnel0. The new tunnel interface is configured to
use IPsec, and the tunnel mode is set to GRE. Configure the other end of the tunnel also as a GRE-over-IPsec
tunnel.
veos(config)#interface tunnel0
veos(config-if-Tu0)#ip address 1.0.3.1/24
veos(config-if-Tu0)#tunnel mode gre
veos(config-if-Tu0)#mtu 1400
veos(config-if-Tu0)#tunnel source 1.0.0.1
veos(config-if-Tu0)#tunnel destination 1.0.0.2
veos(config-if-Tu0)#tunnel ipsec profile vrouter
8. Create the GRE-over-IPsec tunnel interface in a VRF using the
vrf forwarding
command. Create the
VRF, if needed, then create and configure the GRE tunnel interface. Make sure to specify the tunnel key that
is unique across all tunnels.
Note: If tunnels in different VRFs need to share the IPsec connection, specify the same source,
destination, and ipsec profile.
Example:
veos(config)#vrf definition red
veos(config-vrf-red)#rd 1:3
veos(config-vrf-red)#interface tunnel0
veos(config-if-Tu0)#ip address 1.0.3.1/24
veos(config-if-Tu0)#vrf forwarding red
veos(config-if-Tu0)#tunnel mode gre
veos(config-if-Tu0)#mtu 1400
veos(config-if-Tu0)#tunnel source 1.0.0.1
veos(config-if-Tu0)#tunnel destination 1.0.0.2
veos(config-if-Tu0)#tunnel key 100
veos(config-if-Tu0)#tunnel ipsec profile vrouter
veos(config)#vrf definition blue
veos(config-vrf-blue)#rd 1:4
veos(config-vrf-blue)#interface tunnel1
veos(config-if-Tu1)#ip address 1.0.4.1/24
veos(config-if-Tu1)#vrf forwarding blue
veos(config-if-Tu1)#tunnel mode gre
veos(config-if-Tu1)#mtu 1400
veos(config-if-Tu1)#tunnel source 1.0.0.1
veos(config-if-Tu1)#tunnel destination 1.0.0.2
veos(config-if-Tu1)#tunnel key 200
veos(config-if-Tu1)#tunnel ipsec profile vrouter
9. Configure the GRE-over-IPsec tunnel on the peer router.
Configuring VTI IPsec Tunnels
The vEOS Router gives the ability to configure VTI IPsec tunnels between a vEOS Router instance and a third
party peer router instance (such as a Palo Alto firewall VM). First, complete the set up of the tunnel on the vEOS
Router instance, then set up the other end of the tunnel on the third party peer router instance.
vEOS Router Configuration Guide
106
Содержание vEOS
Страница 6: ......
Страница 12: ......
Страница 60: ......
Страница 72: ......
Страница 77: ...7 Select the default network 8 Complete the launch process 77 Server Requirements ...
Страница 94: ...Figure 17 Linux SRIOV PCI Passthrough based Deployment vEOS Router Configuration Guide 94 ...
Страница 124: ......
Страница 128: ......