RUGGEDCOM ROX II
CLI User Guide
Chapter 12
Tunneling and VPNs
Configuring the Connection Ends
419
Section 12.8.9
Configuring the Connection Ends
Each IPsec tunnel has two ends: the local router and the remote router. These are otherwise referred to as the left
and right connections, respectively. Both ends can have the same configuration or a unique configuration.
To configure a connection end for an IPsec tunnel, do the following:
1. Make sure the CLI is in Configuration mode.
2. Navigate to
tunnel » ipsec » connection » {name} » {end}
, where
{name}
is the name of the connection and
{end}
is the either the left (local router) or right (remote router) connection end.
3. Configure the public IP address by configuring the following parameters:
IMPORTANT!
Do not use a Virtual IP Address (VRIP) as the connection's public IP address if
use-virtual-mac
is
enabled under VRRP.
Parameter
Description
type { type }
Synopsis:
{ none, default-route, any, address, hostname }
Default:
none
The public IP address type.
value { value }
Synopsis:
A string 1 to 4095 characters long
The public hostname or IP address.
4. Configure the system public key by configuring the following parameters:
Parameter
Description
type { type }
Synopsis:
{ none, rsasig, certificate-any, certificate }
Default:
none
Key type.
rsa-sig { rsa-sig }
Synopsis:
A string
The RSA signature key name.
rsa-sig-ipsec
Synopsis:
A string 1 to 8192 characters long
The RSA signature in IPsec format.
certificate { certificate }
Synopsis:
A string
The selected certificate.
5. Configure the system identifier by configuring the following parameters:
Parameter
Description
type { type }
Synopsis:
{ default, none, from-certificate, address, hostname, der-asn1-dn, user-fqdn }
Default:
default
The system identifier type. The default value is 'left side public-ip' unless overwritten by
the default connection setting.
value { value }
Synopsis:
A string 1 to 1024 characters long
The hostname, IP address or the Distinguished Name in the certificate.
6. Configure the next hop to the other system by configuring the following parameters:
Содержание RUGGEDCOM ROX II
Страница 2: ...RUGGEDCOM ROX II CLI User Guide ii ...
Страница 4: ...RUGGEDCOM ROX II CLI User Guide iv ...
Страница 39: ...RUGGEDCOM ROX II CLI User Guide Table of Contents xxxix 19 5 VLANs 752 ...
Страница 40: ...Table of Contents RUGGEDCOM ROX II CLI User Guide xl ...
Страница 46: ...Preface RUGGEDCOM ROX II CLI User Guide xlvi Customer Support ...
Страница 96: ...Chapter 2 Using RUGGEDCOM ROX II RUGGEDCOM ROX II CLI User Guide 50 Accessing Maintenance Mode ...
Страница 170: ...Chapter 5 System Administration RUGGEDCOM ROX II CLI User Guide 124 Deleting a Scheduled Job ...
Страница 256: ...Chapter 6 Security RUGGEDCOM ROX II CLI User Guide 210 Enabling Disabling a Firewall ...
Страница 402: ...Chapter 11 Wireless RUGGEDCOM ROX II CLI User Guide 356 Managing Cellular Modem Profiles ...
Страница 646: ...Chapter 13 Unicast and Multicast Routing RUGGEDCOM ROX II CLI User Guide 600 Deleting a Multicast Group Prefix ...
Страница 732: ...Chapter 15 Network Discovery and Management RUGGEDCOM ROX II CLI User Guide 686 Viewing NETCONF Statistics ...
Страница 790: ...Chapter 17 Time Services RUGGEDCOM ROX II CLI User Guide 744 Deleting a Broadcast Multicast Address ...