
Using IPsec on vEOS Router Instances
The vEOS Router establishes and maintains GRE-over-IPsec and VTI IPsec tunnels for the secure or encrypted
communications between peer vEOS Router instances.
Topology
Use the vEOS Router to establish and maintain IPsec tunnels between peer vEOS Router instances in different
topologies of varying complexity.
The diagram below represents a basic IPsec tunnel configuration in which vEOS Router instances are using an
IPsec tunnel.
Figure 18: vEOS Router Instance Using a Basic IPsec Tunnel
The vEOS Router establishes and maintains IPsec tunnels for secure or encrypted communications between
vEOS Router instances and third party devices peer router instances.
The basic process for establishing secure communications using IPsec involves the following tasks:
• Creating IKE Policy for establishing IKE with the peer.
• Specifying the encryption, integrity protocols for the Security Association (SA) Policy.
• Apply IKE and SA policies to a given profile.
• Apply the profile to a tunnel interface.
Configuring IPsec Tunnels on vEOS Router Instances
Use this procedure to configure GRE-over-IPsec or VTI IPsec tunnels on peer vEOS Router instances.
The procedure provides all of the steps required to set up either GRE-over-IPsec or VTI IPsec tunnels. Most of
the steps are the same for both tunnel types (steps 1 through 6 are the same). Step 7 is the step to select the tunnel
type.
Note: vEOS Router by default uses IKE version 2 for all IPsec tunnels. To configure a tunnel that uses
IKE version 1, explicitly configure the vEOS Router to use IKE version 1.
Procedure
Complete the following steps to configure GRE-over-IPsec or VTI IPsec tunnels on vEOS Router instances.
This configuration will be the default IKE version 2 procedure.
1. Use this command to enter IP security mode.
veos(config)#ip security
97
IPsec Support
Содержание vEOS
Страница 6: ......
Страница 12: ......
Страница 60: ......
Страница 72: ......
Страница 77: ...7 Select the default network 8 Complete the launch process 77 Server Requirements ...
Страница 94: ...Figure 17 Linux SRIOV PCI Passthrough based Deployment vEOS Router Configuration Guide 94 ...
Страница 124: ......
Страница 128: ......