6-6
Cisco Secure Router 520 Series Software Configuration Guide
OL-14210-01
Chapter 6 Configuring a VPN Using Easy VPN and an IPsec Tunnel
Enable Policy Lookup
Enable Policy Lookup
Perform these steps to enable policy lookup through AAA, beginning in global configuration mode:
Configure IPsec Transforms and Protocols
A transform set represents a certain combination of security protocols and algorithms. During IKE
negotiation, the peers agree to use a particular transform set for protecting data flow.
During IKE negotiations, the peers search in multiple transform sets for a transform that is the same at
both peers. When such a transform set is found, it is selected and applied to the protected traffic as a part
of both peers’ configurations.
Command or Action
Purpose
Step 1
aaa new-model
Example:
Router(config)#
aaa new-model
Router(config)#
Enables the AAA access control model.
Step 2
aaa authentication login
{
default |
list-name
}
method1
[
method2...
]
Example:
Router(config)#
aaa authentication login
rtr-remote local
Router(config)#
Specifies AAA authentication of selected users at
login, and specifies the method used.
This example uses a local authentication database.
You could also use a RADIUS server for this. For
details, see the
Cisco IOS Security Configuration
Guide
and
Cisco IOS Security Command
Reference
.
Step 3
aaa authorization
{
network | exec | commands
level
| reverse-access | configuration
} {
default |
list-name
} [
method1
[
method2...
]]
Example:
Router(config)#
aaa authorization network
rtr-remote local
Router(config)#
Specifies AAA authorization of all
network-related service requests, including PPP,
and specifies the method of authorization.
This example uses a local authorization database.
You could also use a RADIUS server for this. For
details, see the
Cisco IOS Security Configuration
Guide
and
Cisco IOS Security Command
Reference
.
Step 4
username
name
{
nopassword
|
password
password
| password
encryption-type
encrypted-password
}
Example:
Router(config)#
username Cisco password 0
Cisco
Router(config)#
Establishes a username-based authentication
system.
This example implements a username of
Cisco
with an encrypted password of
Cisco
.
Содержание 520 Series
Страница 15: ...xv Cisco Secure Router 520 Series Software Configuration Guide OL 14210 01 Preface ...
Страница 18: ...xviii Cisco Secure Router 520 Series Software Configuration Guide OL 14210 01 Preface ...
Страница 19: ...P A R T 1 Getting Started ...
Страница 20: ......
Страница 33: ...P A R T 2 Configuring Your Router for Ethernet and DSL Access ...
Страница 34: ......
Страница 103: ...P A R T 3 Configuring Additional Features and Troubleshooting ...
Страница 104: ......
Страница 123: ...P A R T 4 Reference Information ...
Страница 124: ......
Страница 142: ...B 10 Cisco Secure Router 520 Series Software Configuration Guide OL 14210 01 Appendix B Concepts Access Lists ...
Страница 162: ...Index IN 8 Cisco Secure Router 520 Series Software Configuration Guide OL 14210 01 ...