
AWS Specific Cloud Configuration
1. Internet Key Exchange Configuration
The address of the external interface for a customer gateway must be a static address. the customer gateway can
reside behind a device performing network Address Translation (NAT) To ensure that NAT Transversal (NAT-T)
can function, add, and update the firewall rules, allow UDP port 4500. Disable NAT-T if the customer gateway
is not behind a NAT gateway.
• Authentication Method: Pre-Shared Key
• Pre-Shared Key: LwYbARmDJmpFGOrAbPGk2uQiWwvbmfU
• Authentication Algorithm: sha1
• Encryption Algorithm: aes-128-cbc
• Lifetime: 28800 seconds
• Phase 1 Negotiation Method: main
• Perfect Forward Secrecy: Diffie-Hellman Group 2
AWS Specific Cloud Configuration Modifications
1. Internet Key Exchange SA Configuration
The address of the external interface for the customer gateway must be a static address. The customer gateway
can reside behind a device performing Network Address Translation (NAT). To make sure that NAT traversal
(NAT-T) functions correctly, add or update the firewall rule to allow UDP port 4500. Disable NAT-T if the
customer gateway is not behind a NAT gateway.
Use the following sample configuration files to set up an Internet key exchange SA configuration.
• Authentication Method: Pre-shared Key
• Pre-shard Key: LwYbARmDJmpFGAOrAbPGk2uQiWwvbmfU
• Authentication Algorithm: sha1
• Encryption Algorithm: aes-128-cbc
• Lifetime: 28800 seconds
• Phase 1 Negotiation Mode: main
• Perfect Forward Secrecy: Diffie-Hellman Group 2
2. IPsec Configuration
Use the following sample configuration files to configure the IPsec. Modification of the sample configuration
files may be need to take advantage of additionally supported IPsec parameters for encryption, such as
AES256 and other DH groups like 2, 5, 14-18, 22, 23, and 24.
• Protocol: esp
• Authentication Algorithm: hmac-sha-96
• Encryption Algorithm: aes-128-cbc
• Lifetime: 3600 seconds
• Mode: tunnel
• Perfect Forward Secrecy: Diffie-Hellman Group2
The IPsec Dead Peer Detection (DPD) is enabled on the AWS Specific Cloud endpoint. Configure the DPD
on your endpoint as follows:
• DPD interval: 10
• DPD Retries: 3
vEOS Router Configuration Guide
122
Содержание vEOS
Страница 6: ......
Страница 12: ......
Страница 60: ......
Страница 72: ......
Страница 77: ...7 Select the default network 8 Complete the launch process 77 Server Requirements ...
Страница 94: ...Figure 17 Linux SRIOV PCI Passthrough based Deployment vEOS Router Configuration Guide 94 ...
Страница 124: ......
Страница 128: ......