Configuration Guide
7. IPSec Tunneling
Version 7.2
49
Security Setup
7.1.4 Configuring IPSec with IKEv2
The MSBR supports Internet Key Exchange (IKE) version 2. With IKEv2, the MSBR supports
configuring the peer by IP address or FQDN.
For the identity of the IKEv2 peer, the MSBR supports:
IP address
FQDN
7.1.4.1 Configuration Example
This configuration example is based on the following topology:
The IP address of the "MSBR HQ" is constant (fixed), while the IP address of the "MSBR
Branch" may be dynamic and change every time the interface PPPoE 0 reconnects. In this
scenario, the identity of the MSBR Branch should therefore, not be by IP address because it
changes; instead, it should be by FQDN or email address.
Configuration of MSBR Branch:
configure data
access-list ipsec permit ip 192.168.0.0 0.0.0.255
192.168.100.0 0.0.0.255 log
access-list all_but_ipsec deny ip 192.168.0.0 0.0.0.255
192.168.100.0 0.0.0.255 log
access-list all_but_ipsec permit ip any any log
crypto isakmp obscured-key Vhc2aWtpb2lr address 82.80.170.113
crypto isakmp identity fqdn home.timg.pro
crypto isakmp policy 1
encr aes 256
authentication pre-share
hash sha
group 5
lifetime 3600
Содержание Mediant 500L MSBR
Страница 2: ......
Страница 4: ...Mediant MSBRs 4 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 8: ...Mediant MSBRs 8 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 12: ...Mediant MSBRs 12 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 16: ...Mediant MSBRs 16 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 18: ...Mediant MSBRs 18 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 24: ...Mediant MSBRs 24 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 28: ...Mediant MSBRs 28 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 54: ...Mediant MSBRs 54 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 62: ...Mediant MSBRs 62 Document LTRT 31828 Security Setup This page is intentionally left blank...
Страница 72: ...Mediant MSBRs 72 Document LTRT 31828 Security Setup This page is intentionally left blank...