142
Cisco 3900 Series, Cisco 2900 Series, and Cisco 1900 Series Integrated Services Routers Generation 2 Software Configuration Guide
Chapter Configuring Security Features
Configuring VPN
Apply the Crypto Map to the Physical Interface
The crypto maps must be applied to each interface through which IPSec traffic flows. Applying the
crypto map to the physical interface instructs the router to evaluate all the traffic against the security
associations database. With the default configurations, the router provides secure connectivity by
encrypting the traffic sent between remote sites. However, the public interface still allows the rest of the
traffic to pass and provides connectivity to the Internet.
To
apply a crypto map to an interface
,
follow these steps
,
beginning in global configuration mode
.
SUMMARY STEPS
1.
interface
type number
2.
crypto map
map-name
3.
exit
DETAILED STEPS
Step 4
exit
Example:
Router(config-crypto-map)# exit
Router(config)#
Returns to global configuration mode.
Step 5
crypto map
map-name seq-num
[
ipsec-isakmp
]
[
dynamic
dynamic-map-name
] [
discover
]
[
profile
profile-name
]
Example:
Router(config)# crypto map static-map 1
ipsec-isakmp dynamic dynmap
Router(config)#
Creates a crypto map profile.
Command or Action
Purpose
Command or Action
Purpose
Step 1
interface
type number
Example:
Router(config)# interface fastethernet 4
Router(config-if)#
Enters the interface configuration mode for the
interface to which you are applying the crypto
map.