Configuration Of An Ip Interface And The Ip Router For Ipsec; Displaying Ipsec Configuration Information - Patton electronics SmartWare R.3.20 Software Configuration Manual

Software for smartnode series
Table of Contents

Advertisement

SmartWare Software Configuration Guide
Configuration of an IP interface and the IP router for IPsec
The IP interface that provides connectivity to the IPsec peer, must now activate the outgoing ACL profile con-
figured in the previous section. Furthermore, the IP router must have a route for the remote network that
points to the respective IP interface.
Procedure: To activate the outgoing ACL profile and to establish the necessary route
Mode: Configure
Step
node (cfg)#context ip router
1
node (ctx-ip)[router]#interface if-name
2
node (if-ip)[ if-name ]# use profile acl
3
name out
node (if-ip)[ if-name ]#context ip router
4
node (ctx-ip)[router]#route remote-net-
5
work-address remote-network-mask if-name 0
optional
Example: Activate outgoing ACL and establish route
The following example configures an outgoing ACL profile that interconnects the two private networks
192.168.1/24 and 172.16/16.
node(cfg)#context ip router
node(ctx-ip)[router]#interface WAN
node(if-ip)[WAN]#use profile acl VPN_Out out
node(if-ip)[WAN]#context ip router
node(ctx-ip)[router]#route 172.16.0.0 255.255.0.0 WAN 0
Displaying IPsec configuration information
This section shows how to display and verify the IPsec configuration information.
Procedure: To display IPsec configuration information
Mode: Configure
Step
1
node (cfg)#show profile ipsec-trans-
optional
form
2
node(cfg)#show profile ipsec-policy-
optional
manual
VPN configuration task list
Command
Command
Purpose
Enter IP context
Create/enter the IP interface if-name
Activate the outgoing ACL profile name
Enter IP context
Creates a route for the remote network that
points the above IP interface if-name
You can omit this setting if the default route
already points to this IP interface or to a next hub
reachable via this IP interface, and if there is no
other route.
Make also sure that the IP router knows how to
reach the peer of the secured communication.
Usually, a default route does this job.
Purpose
Displays all IPsec transformation profiles
Displays all IPsec policy profiles
25 • VPN configuration
287

Advertisement

Table of Contents
loading

This manual is also suitable for:

Smartware release 3.20

Table of Contents