Example For Ike Aggressive Mode And Nat Traversal - 3Com MSR 50 Series Configuration Manual

3com msr 30-16: software guide
Hide thumbs Also See for MSR 50 Series:
Table of Contents

Advertisement

1910
C
101: IKE C
HAPTER
Example for IKE
Aggressive Mode and
NAT Traversal
n
ONFIGURATION
[RouterA-ike-proposal-10] sa duration 5000
2 Configure Router B
# Configure an IKE peer.
<RouterB> system-view
[RouterB] ike peer peer
[RouterB-ike-peer-peer] pre-shared-key abcde
[RouterB-ike-peer-peer] remote-address 1.1.1.1
With the above configuration, Router A and Router B should be able to perform
IKE negotiation. Router A is configured with proposal 10 which uses the
authentication algorithm of MD5, but Router B has only a default IKE proposal
which uses the authentication algorithm of SHA. Therefore, Router B has no
proposal matching proposal 10 of Router A, and the two routers have only one
pair of matching proposals, namely the default IKE proposals. In addition, the two
routers are not required to have the same ISAKMP SA lifetime, they will negotiate
one.
Network requirements
The LAN of the branch office is connected to the Intranet in the headquarters
through a leased line. The Serial 2/0 interface of Router A has a fixed public IP
address and Router B obtains an IP address dynamically.
As the IP address obtained by the branch is a private one and the IP address of
the Serial 2/0 interface on Router A is a public one, you must enable NAT
traversal on Router B.
For higher security, IKE is used to create an IPSec tunnel.
For the purpose of highlighting the configurations of IKE aggressive mode and
NAT traversal, routers in this example are interconnected through their serial
interfaces across the Internet and one end is configured to obtain an IP address
dynamically. You can refer to this example if you access the Internet using the
dial-up or broadband service.
Network diagram
Figure 556 Network diagram for configuring IKE aggressive mode and NAT traversal
Branch
Configuration procedure
1 Configure Router A
# Specify a name for the local security gateway.
<RouterA> system-view
[RouterA] ike local-name routera
# Configure an ACL.
NAT
Leased line
S2/0
Router B
ppp- negotiate
Internet
S2/0
Router A
100 .0.0.1/16
Headquarters

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents