12. Optionally, define the egress access control list to protect the device from sending
traffic that is not allowed to the public interface:
a. Permit IKE Traffic (UDP port 500) for VPN control traffic (IKE)
Note:
If you are using NAT Traversal, you also need to open UDP port 4500
and 2070.
b. Permit ESP traffic (IP Protocol ESP) for VPN data traffic (IPSEC)
c. Permit ICMP traffic, to support the PMTU application, for a better
fragmentation process
d. For each private subnet add a permit rule, with the source being the
private subnet, and the destination being any
e. Define all other traffic (default rule) as deny in order to protect the device
from sending non-secure traffic
13. Activate the crypto list, the ingress access control list, and the egress access control
list, on the public interface.
Failover VPN topology using a peer-group example
!
! Define the Private Subnet1
!
interface vlan 1
description “Branch Subnet1”
ip address 10.0.10.1 255.255.255.0
icc-vlan
pmi
exit
!
! Define the Private Subnet2
!
interface vlan 2
description “Branch Subnet2”
ip address 10.0.20.1 255.255.255.0
exit
!
! Define the Public Subnet
!
interface fastethernet 10/3
ip address 100.0.0.2 255.255.255.0
exit
!
! Define the default gateway the public interfce
!
ip default-gateway 100.0.0.1
!
! We wish to check 5 hosts in the Corporate intranet behind the current VPN
! remote peer, and if 2 or more hosts don’t work then keepalive-track will fail ,
! and we will move to the next peer in the peer-group
IPSec VPN
544 Administering Avaya G430 Branch Gateway
October 2013
Содержание G430
Страница 1: ...Administering Avaya G430 Branch Gateway Release 6 3 03 603228 Issue 5 October 2013 ...
Страница 12: ...12 Administering Avaya G430 Branch Gateway October 2013 ...
Страница 214: ...Ethernet ports 214 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 232: ...System logging 232 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 246: ...VoIP QoS 246 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 250: ...Modems and the Branch Gateway 250 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 302: ...Emergency Transfer Relay ETR 302 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 556: ...IPSec VPN 556 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 604: ...Policy based routing 604 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 610: ...Synchronization 610 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 668: ...Traps and MIBs 668 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...