Configuring the VPN DNS topology
Procedure
1. Define the private VLAN1 and VLAN2 interfaces (IP address and mask), and define
one of them as the PMI and ICC-VLAN.
2. Define the public FastEthernet10/3 interface (IP address and mask).
3. Define the default gateway (the IP of the next router).
4. Define the DNS name-server-list and the IP address of the DNS server.
Note:
Alternatively, you can use DHCP Client or PPPoE to dynamically learn the DNS
server’s IP address. Use the
ip dhcp client request
command when using
DHCP client, or use the
ppp ipcp dns request
command when using
PPPoE.
5. Define the ISAKMP policy, using the
crypto isakmp policy
command.
6. Define the remote peer with FQDN, using the
crypto isakmp peer address
command, including:
• the pre-shared key
• the ISAKMP policy
7. Define the IPSEC transform-set, using the
crypto ipsec transform-set
command.
8. Define the crypto map, using the
crypto map
command.
9. Define the crypto list as follows:
a. Set the local address to the public interface name (for example, FastEthernet
10/3.0)
b. For each private interface, define an ip-rule using the following format:
•
source-ip
<private subnet>
<private subnet wild card mast>
. For
example, 10.10.10.0 0.0.0.255
• destination-ip any
• protect crypto map 1
10. Define the ingress access control list (ACL) to protect the device from Incoming
traffic from the public interface, as follows:
a. Permit DNS traffic to allow clear (unencrypted) DNS traffic
b. Permit IKE Traffic (UDP port 500) for VPN control traffic (IKE)
c. Permit ESP traffic (IP Protocol ESP) for VPN data traffic (IPSEC)
IPSec VPN
Administering Avaya G430 Branch Gateway
October 2013 537
Содержание G430
Страница 1: ...Administering Avaya G430 Branch Gateway Release 6 3 03 603228 Issue 5 October 2013 ...
Страница 12: ...12 Administering Avaya G430 Branch Gateway October 2013 ...
Страница 214: ...Ethernet ports 214 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 232: ...System logging 232 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 246: ...VoIP QoS 246 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 250: ...Modems and the Branch Gateway 250 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 302: ...Emergency Transfer Relay ETR 302 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 556: ...IPSec VPN 556 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 604: ...Policy based routing 604 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 610: ...Synchronization 610 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Страница 668: ...Traps and MIBs 668 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...