Configuration Guide
7. IPSec Tunneling
Version 7.2
45
Security Setup
7.1.3.1.5 Device PKI Configuration Example
The following is an example of the configuration of IPSec using PKI authentication between
two routers using a GRE tunnel. Both devices have an NTP server configured, and
certificates were imported as described in the previous sections.
Figure 7-5: Device PKI Configuration Example
Configuration of MSBR-31 is as follows:
configure data
access-list IPSEC permit gre any any
access-list ALL_BUT_IPSEC deny gre any any
access-list ALL_BUT_IPSEC permit ip any any
crypto isakmp policy 1
encr aes 256
authentication rsa-sig
hash sha
group 5
lifetime 3600
exit
crypto ipsec transform-set crypto_set esp-aes 256 esp-sha-hmac
mode tunnel
exit
crypto map MAP1 1 ipsec-isakmp
set peer 10.4.40.86
set transform-set crypto_set
set security-association lifetime seconds 3600
match address IPSEC
set default-route
exit
interface GigabitEthernet 0/0
ip address 10.31.2.31 255.255.255.0
Содержание Mediant 500L MSBR
Страница 2: ......
Страница 4: ...Mediant MSBRs 4 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 8: ...Mediant MSBRs 8 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 12: ...Mediant MSBRs 12 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 16: ...Mediant MSBRs 16 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 18: ...Mediant MSBRs 18 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 24: ...Mediant MSBRs 24 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 28: ...Mediant MSBRs 28 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 54: ...Mediant MSBRs 54 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 62: ...Mediant MSBRs 62 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 72: ...Mediant MSBRs 72 Document LTRT 31828 Security Setup This page is intentionally left blank...