D-Link DI-1750 Reference Manual page 368

Hide thumbs Also See for DI-1750:
Table of Contents

Advertisement

Model Name
If you create more than one crypto map entry for a given interface, use the seq-num of each map entry
to rank the map entries: the lower the seq-num, the higher the priority. At the interface that has the
crypto map set, traffic is evaluated against higher priority map entries first. You must create multiple
crypto map entries for a given interface if any of the following conditions exist:
If different data flows are to be handled by separate IPSec peers.
If you want to apply different IPSec security to different types of traffic (to the same or separate IPSec
peers); for example, if you want traffic between one set of subnets to be authenticated, and traffic
between another set of subnets to be both authenticated and encrypted. In this case the different types
of traffic should have been defined in two separate access lists, and you must create a separate crypto
map entry for each crypto access list.
If you are not using IKE to establish a particular set of security associations, and want to specify
multiple access list entries, you must create separate access lists (one per permit entry) and specify a
separate crypto map entry for each access list.
8.4.6 Creating Crypto Map Entries Manually
The use of manual security associations is a result of a prior arrangement between the users of the
local router and the IPSec peer. The two parties may wish to begin with manual security associations,
and then move to using security associations established via IKE, or the remote party's system may not
support IKE. If IKE is not used for establishing the security associations, there is no negotiation of
security associations, so the configuration information in both systems must be the same in order for
traffic to be processed successfully by IPSec.
The local router can simultaneously support manual and IKE-established security associations.
To create crypto map entries to establish manual security associations, use the following commands
starting in global configuration mode:
- 366 -

Advertisement

Table of Contents
loading

This manual is also suitable for:

Di-2621Di-2630Di-3660

Table of Contents