Mediant MSBRs
30
Document #: LTRT-31828
Security Setup
Command
Description
(config-isakmp)# group 2
Configures the Diffie-Hellman group.
(config-isakmp)# ike v1
Selects IKE version 1 or IKE version 2
(config-isakmp)# lifetime 3600
The lifetime is the period of re-authentication. In
this case, the tunnel is re-authenticated every
hour.
(config-isakmp)# exit
Exit policy configuration level.
(config-data)# crypto ipsec
transform-set crypto_set1 esp-aes
128 esp-sha-hmac
Configure the transform set, and select
encrypting type and key length in bits.
(cfg-crypto-trans)# mode tunnel
Select the operation mode.
(cfg-crypto-trans)# exit
Exit transform set configuration level.
(config-data)# crypto map MAP1 1
ipsec-isakmp
Configure the crypto map.
(config-crypto-map)# set peer
180.1.100.21
Configure the peer IP address.
(config-crypto-map)# set
transform-set crypto_set1
Configure the transform set.
(config-crypto-map)# set
security-association lifetime
seconds 28000
Configure the lifetime timer. When the timer
expires, re authentication commences.
(config-crypto-map)# match
address ipsec
Assign an ACL to the transform set.
(config-crypto-map)# exit
Exit the transform set configuration level.
(config-data)# crypto isakmp key
P@ssw0rd address 180.1.100.21
Configure the key from the IPSec.
(config-data)# interface
GigabitEthernet 0/0
Configure interface g0/0.
(conf-if-GE 0/0)# crypto map MAP1
Assign the IPSec policy to the interface.
(conf-if-GE 0/0)# ip tcp adjust-
mss 1374
Ensures that IPSec traffic is accelerated,
resulting in high performance of the IPSec
traffic.
Note:
This is applicable only to Mediant 500Li
MSBR.
# show data crypto status
Displays the IPSec status.
Содержание Mediant 500L MSBR
Страница 2: ......
Страница 4: ...Mediant MSBRs 4 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 8: ...Mediant MSBRs 8 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 12: ...Mediant MSBRs 12 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 16: ...Mediant MSBRs 16 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 18: ...Mediant MSBRs 18 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 24: ...Mediant MSBRs 24 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 28: ...Mediant MSBRs 28 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 54: ...Mediant MSBRs 54 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 62: ...Mediant MSBRs 62 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 72: ...Mediant MSBRs 72 Document LTRT 31828 Security Setup This page is intentionally left blank...