destination-ip any
source-ip host <Branch Subnet2> <Branch Subnet2 Mask>
composite-operation Permit
exit
ip-rule default
composite-operation deny
exit
exit
interface vlan 1.1
ip-address <Branch Subnet1> <Branch Subnet1 Mask>
pmi
icc-vlan
exit
interface vlan 1.2
ip-address <Branch Subnet2> <Branch Subnet2 Mask>
exit
interface FastEthernet 10/3
encapsulation PPPoE
traffic-shape rate 256000
ip Address <Branch Office Public Internet Static IP Address>
<Branch Office Public Internet
network mask>
ip crypto-group 901
ip access-group 301 in
ip access-group 302 out
exit
ip default-gateway FastEthernet 10/3 high
Dynamic local peer IP
When the number of static IP addresses in an organization is limited, the ISP allocates
temporary IP addresses to computers wishing to communicate over IP. These temporary
addresses are called dynamic IP addresses.
The Branch Gateway IPSec VPN feature provides dynamic local peer IP address support. To
work with dynamic local peer IP, you must first configure some prerequisites and then instruct
the Branch Gateway to learn the IP address dynamically using either PPPoE or DHCP
client.
Note:
When working with dynamic local peer IP, you must verify that it is the Branch Gateway that
initiates the VPN connection. The VPN peer cannot initiate the connection since it does not
know the Branch Gateway’s IP address. To maintain the Branch Gateway as the initiator,
do one of the following:
• Specify
continuous channel
in the context of the VPN peer, to maintain the IKE phase
1 connection even when no traffic is sent (see
on page 512).
• Maintain a steady transmission of traffic by sending GRE keepalives or employing object
tracking.
Related topics:
Prerequisites for dynamic local peer IP
on page 510
Configuring dynamic local peer IP on a PPPoE interface
Configuring dynamic local peer IP for a DHCP Client
on page 511
IPSec VPN
Administering Avaya G430 Branch Gateway
October 2013 509
Содержание G430
Страница 1: ...Administering Avaya G430 Branch Gateway Release 6 3 03 603228 Issue 5 October 2013 ...
Страница 12: ...12 Administering Avaya G430 Branch Gateway October 2013 ...
Страница 214: ...Ethernet ports 214 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 232: ...System logging 232 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 246: ...VoIP QoS 246 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 250: ...Modems and the Branch Gateway 250 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 302: ...Emergency Transfer Relay ETR 302 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 556: ...IPSec VPN 556 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 604: ...Policy based routing 604 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 610: ...Synchronization 610 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 668: ...Traps and MIBs 668 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...