Configuring IPSec VPN
568 Administration for the Avaya G250 and Avaya G350 Media Gateways
4. Use the
ip-rule
command, followed by an index number from
1
to
1000
, to enter the
context of an ip-rule (and to create the ip-rule if it does not exist).
!
Important:
Important:
It is mandatory to create at least one ip-rule.
For example:
5. Configure ip-rule parameters as follows:
●
Use the
description
command to assign a description to the ip-rule.
●
To specify a range of source and destination IP addresses to which the rule applies,
use the
source-ip
and
destination-ip
commands, followed by the IP range
criteria. The IP range criteria can be one of the following:
-
A single address
. Type
host
, followed by an IP address, to set a single IP
address to which the rule applies.
-
A wildcard
. Type
host
, followed by an IP address using wildcards, to set a range
of IP addresses to which the rule applies.
-
All addresses
. Type
any
to apply the rule to all IP addresses.
Use the
no
form of the appropriate command to return to the default value,
any
.
●
Define the action by specifying whether to protect traffic that matches the source and
destination addresses, using one of the following commands:
-
no protect
. Do not protect traffic that matches the source and destination
addresses.
-
protect crypto map
crypto-map-id
. Protect traffic that matches the source
and destination addresses. The specified crypto map specifies how to secure the
traffic. For instructions on configuring crypto maps, see
Configuring crypto
maps
on page 565.
For example:
●
For rules whose action is
no protect
, you can fine-tune the definition of packets that
match this rule by using the following commands. For a full description of the
G350-001(Crypto 901)# ip-rule 10
G350-001(Crypto 901/ip rule 10)#
G350-001(Crypto 901/ip rule 10)# description “vpn tunnel to uk main
office”
Done!
G350-001(Crypto 901/ip rule 10)# source-ip 10.1.0.0 0.0.255.255
Done!
G350-001(Crypto 901/ip rule 10)# destination-ip any
Done!
G350-001(Crypto 901/ip rule 10)# protect crypto map 1
Done!
Содержание Media Gateway G250
Страница 1: ...Administration for the Avaya G250 and Avaya G350 Media Gateways 03 300436 Issue 5 June 2008 ...
Страница 24: ...Contents 24 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 32: ...Introduction 32 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 38: ...Configuration overview 38 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 128: ...Basic device configuration 128 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 210: ...Configuring Standard Local Survivability SLS 210 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 244: ...Configuring logging 244 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 258: ...Configuring VoIP QoS 258 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 354: ...Configuring Emergency Transfer Relay ETR 354 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 370: ...Configuring SNMP 370 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 402: ...Configuring advanced switching 402 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 486: ...Configuring monitoring applications 486 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 548: ...Configuring the router 548 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 664: ...Configuring policy 664 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 682: ...Configuring policy based routing 682 Administration for the Avaya G250 and Avaya G350 Media Gateways ...
Страница 686: ...Setting synchronization 686 Administration for the Avaya G250 and Avaya G350 Media Gateways ...