Example 3: Joining Two Networks With An Ipsec Tunnel Using Multiple Ipsec Proposals - Avaya 1000 Series Configuration Manual

Secure router
Hide thumbs Also See for 1000 Series:
Table of Contents

Advertisement

IPSec EXAMPLES
Networks1> show crypto ipsec sa all detail
Example 3: Joining Two Networks with an IPSec Tunnel
using Multiple IPSec Proposals
The following example demonstrates how a security gateway can use multiple IPSec (phase2)
proposals to form an IP security tunnel to join two private networks: 10.0.1.0/24 and
10.0.2.0/24.
IKE Proposal offered by both Networks1 and Networks2:
Example
Phase 1: 3DES and SHA1
IPSec Proposals offered by Networks1:
Example
• Phase 2: Proposal1: IPSec ESP with DES and HMAC-SHA1
• Phase 2: Proposal2: IPSec ESP with AES (256-bit) and HMAC-SHA1
IPSec Proposal offered by Networks2:
Example
Phase 2: Proposal1: IPSec ESP with AES (256-bit) and HMAC-SHA1
In this example, the Networks1 router offers two IPSec proposals to the peer while the
Networks2 router offers only one proposal. As a result of quick mode negotiation, the two
routers are expected to converge on a mutually acceptable proposal, which is the proposal
"IPSec ESP with AES (256-bit) and HMAC-SHA1" in this example.
148
Avaya Secure Router 1000 Series Configuration Guide
December 2010

Advertisement

Table of Contents
loading

Table of Contents