Avaya G250 Administration page 432

Media gateway
Hide thumbs Also See for G250:
Table of Contents

Advertisement

Configuring IPSec VPN
Configuring the failover VPN topology using a peer-group
To configure the failover VPN topology using a peer-group:
1. Define the private Vlan1 and Vlan2 interfaces (ip address and mask), and define one of
them as the PMI and ICC-VLAN.
2. Define the public FastEthernet 10/2 interface (ip address and mask).
3. Define the default gateway (the IP address of the next router).
4. Define the object tracking configuration, and define when an object tracker is considered
down, as follows:
Define a track list that will monitor (by ICMP) 5 hosts behind the specific peer. If two or more
hosts are not working then the object tracker is down. The G250/G350 will then pass on to
the next peer in the peer group list.
5. Define the ISAKMP policy using the crypto isakmp policy command.
6. Define the 3 remote peers using the crypto isakmp peer address command, and
specify for each one:
the pre-shared key
the ISAKMP policy
keepalive track. This track is the object tracker that checks if the peer is still alive. If an
active peer is considered dead, the next peer in the peer group becomes the active peer.
7. Define a peer group that include all three remote peers, using the crypto isakmp
peer-group command.
8. Define the IPSEC transform-set using the crypto ipsec transform-set command.
9. Define the Crypto map entity using the crypto map command.
10. Define the crypto-list as follows:
Set the local address to the public interface name (for example, FastEthernet 10/2.0).
For each private interface, define an ip-rule using the following format:
source-ip <private subnet> <private subnet wild card mast>.
For example: 10.10.10.0 0.0.0.255
destination-ip any
protect crypto map 1
11. Define the Ingress access control list to protect the device from incoming traffic from the
public interface, as follows:
Permit IKE Traffic (UDP port 500) for VPN control traffic (IKE).
Note:
If you are using NAT Traversal you also need to open UDP port 4500 and 2070.
Note:
Permit ESP traffic (IP Protocol ESP) for VPN data traffic (IPSEC).
432 Administration for the Avaya G250 and Avaya G350 Media Gateways

Advertisement

Table of Contents
loading

This manual is also suitable for:

G350

Table of Contents