CHAPTER 25. IPSEC
258
© SAMSUNG Electronics Co., Ltd.
Securely Managing the Ubigate iBG3026 System
Example
This example demonstrates how to manage a router through an IP security
tunnel. Steps are presented for configuring the Router and NW2 routers to
assist any host on the LAN side of Networks-2 to manage the Router router
through the IP security tunnel.
The security requirements are:
Phase 1: 3DES with SHA1
Phase 2: IPSec ESP with 128-bit AES and HMAC-SHA1
Figure 25.1 Tunnel Mode Between Tow Security Gateways-Single Proposal
1.
Configure a WAN bundle of network type untrusted.
Router/configure# interface bundle wan1
Router/configure/interface/bundle wan1# link t1 0/2/0
Router/configure/interface/bundle wan1# encapsulation ppp
Router/configure/interface/bundle wan1# ip address
172.16.0.1 24
Router/configure/interface/bundle wan1# crypto untrusted
Router/configure/interface/bundle wan1# exit
2.
Configure the Ethernet interface with trusted network type.
Router/configure# interface ethernet 0/1
Router/configure interface/ethernet 0/1# ip address 10.0.1.1
24
Router/configure/interface/ethernet(0/1)# crypto trusted
Router/configure/interface/ethernet(0/1)# exit
Router 1
Router 2
IPSec ESP
UNTRUSTED
TRUSTED
TRUSTED
Network
10.0.1.0/24
Network
10.0.2.0/24
172.16.0.1
172.16.0.2
Содержание Ubigate iBG3026
Страница 1: ......
Страница 16: ...INTRODUCTION XIV SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 32: ...TABLE OF CONTENTS XXX SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 34: ......
Страница 42: ...CHAPTER 1 Basic Configuration 8 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 64: ...CHAPTER 4 System Logging 30 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 70: ...CHAPTER 5 RMON Configuration 36 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 72: ......
Страница 94: ...CHAPTER 7 WAN Interfaces 58 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 110: ......
Страница 126: ...CHAPTER 10 Layer 2 Switching 88 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 156: ...CHAPTER 15 BGP 118 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 178: ...CHAPTER 17 VRRP 140 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 260: ...CHAPTER 20 VLAN forwarding with QoS 222 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 262: ......
Страница 268: ...CHAPTER 21 Authentication Authorization Accounting 228 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 288: ...CHAPTER 23 Firewall NAT 248 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 346: ......
Страница 378: ...CHAPTER 27 VoIP Gateway Management 336 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 706: ...CHAPTER 36 Management 664 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 716: ...CHAPTER 37 Survivable Telephony 674 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Страница 718: ...EQBD 000026 Ed 00 ...