ESR-Series. User manual
154
•
Hub tunnels. This means that branches can communicate with each other directly, without the need for traffic
to pass through the Hub.
To establish such a connection, clients (NHC) over an encrypted IPsec tunnel send their internal (tunnel)
address and external (NBMA) address to the NHRP server (NHS). When a client wants to connect to another
NHC, it sends a request to the server to find out its external address. Having received a response from the
server, the client can now independently establish a connection to the remote branch.
9.2.1 Configuration algorithm
Step
Description
Command
Keys
1
Check the availability of 'external' IP
addresses located on physical
interfaces.
2
Prepare IPsec tunnels for use with
dynamic GRE tunnels.
See section
.
2
Create a GRE tunnel and switch to its
configuration mode.
esr(config)# tunnel gre <INDEX>
<INDEX> – tunnel identifier.
3
Switch the GRE tunnel to multipoint
mode.
esr(config-gre )# multipoint
4
Set an open password for NHRP
packets (optional).
esr(config-gre)# ip nhrp
authentication <WORD>
<WORD> – unencrypted
password, set by the string of
[1..8] characters, may include
[0-9a-fA-F] characters.
5
Specify the time during which a record
about this client will exist on the NHS
(optional).
esr(config-gre)# ip nhrp holding-
time <TIME>
<TIME> – the time in seconds
during which a record about
this client will exist on the
server takes the values
[1..65535].
Default value: 7200
6
Set the 'logic (tunnel)' address of the
NHRP server.
esr(config-gre)# ip nhrp nhs
<ADDR> [ no-registration ]
<ADDR/LEN> – address,
defined as AAA.BBB.CCC.DDD/
EE where each part AAA-DDD
takes values of [0..255] and EE
takes values of [1..32];
no-registration
— do not
register on the NHRP
server.
7
Match the 'internal' tunnel address with
the 'external' NBMA address.
esr(config-gre)# ip nhrp map
<ADDR> <ADDR>
<ADDR> – IP address, defined
as AAA.BBB.CCC.DDD where
each part takes values of
[0..255].
Содержание ESR Series
Страница 218: ...ESR Series User manual 218 ...
Страница 234: ...ESR Series User manual 234 In addition to RIP protocol configuration open UDP port 520 in the firewall ...
Страница 306: ...ESR Series User manual 306 Parameter targeted LDP Hold timer 45 seconds Keepalive holdtime 180 seconds ...
Страница 452: ...ESR Series User manual 452 Step Description Command Keys 4 Enable Tracking object esr config tracking enable ...
Страница 514: ...ESR Series User manual 514 esr show ntp peers ...