Vpn Interface Sub-Commands; Configuring A Simple Vpn Site-To-Site Application - Enterasys Security Router X-PeditionTM User Manual

Enterasys security router user's guide
Table of Contents

Advertisement

Configuring a Simple VPN Site-to-Site Application

VPN Interface Sub-Commands

The following sub-commands are available at VPN Interface mode:
ip firewall
ip address-negotiated
ip address
ip multicast-redirect
ip nat
ip rip
ip unnumbered
ip split-horizon
ip ospf
tunnel
set heartbeat
set protocol (ipsec or gre)
set active
set user
set peer
Configuring a Simple VPN Site-to-Site Application
The following main steps describe how to configure a simple Site-to-Site VPN between two XSRs,
as illustrated in
Encrypt Branch-site traffic on the 63.81.66.0/24 network to Central site networks (63.81.64.0/
24, 63.81.68.0/24, 141.154.196.64/28)
Set up IPSec/IKE policy with pre-shared keys
Configure cryptographic algorithms (transform-sets) and IPSec mode
Configure the VPN interface and crypto maps
1.
Generate a master encryption key as described in
page 14-20. This need only be done once on the router.
2.
Begin Central Site configuration of all necessary physical and system requirements, including
physical IP addresses, routing (default route and RIP or OSPF), and standard ACLs. This
example offers numerous options.
3.
Configure Access Lists 120, 130, and 140 to define the particular traffic to be protected by the
tunnel. The ACLs allow a range of IP addresses on the VPN. In the context of VPN
14-32 Configuring the Virtual Private Network
+
Set of commands to configure the firewall
+
Sets the VPN interface's IP address to be negotiated
+
Specifies an IP address on the VPN interface
+
Redirects multicast to a unicast address
+
Specifies NAT rules on the VPN interface
+
Configures RIP routing on the VPN port
+
Enables IP processing on a serial port without assigning it an explicit IP address
+
Enables split horizon mechanism
+
Set of commands to configure OSPF routing
+
Command and sub-commands configure a site-to-site VPN tunnel on a point-to-point interface
+
Enables and configures tunnel connectivity monitoring
+
Brings the tunnel up
+
Designates the user name when initiating a tunnel and obtains credentials from the AAA subsystem
+
Sets the IP address of the peer
Figure
14-11:
Figure 14-11
Branch Office
FastEthernet 1
XSR
63.81.66.1
63.81.66.0/24
+
Selects a tunnel protocol
Site-to-Site Example
FastEthernet 2
Internet
1.1.1.1
Central Site
FastEthernet 2
1.1.1.2
FastEthernet 1
141.154.196.78
63.81.64.0/24 63.81.68.0/24
"Master Encryption Key Generation"
XSR
on

Advertisement

Table of Contents
loading

This manual is also suitable for:

X-pedition xsr

Table of Contents