Example 5: Configuring Ipsec Remote Access To Corporate Lan With Mode-Configuration Method - Avaya 1000 Series Configuration Manual

Secure router
Hide thumbs Also See for 1000 Series:
Table of Contents

Advertisement

Example 5: Configuring IPSec Remote Access to Corporate LAN with Mode-Configuration Method

Networks1> show crypto dynamic clients
Client Address
--------------
192.168.107.105 david@abc-corp...
Networks1> show crypto ike sa all
Networks1> show crypto ike sa all detail
Networks1> show crypto ipsec sa all
Networks1> show crypto ipsec sa all detail
Example 5: Configuring IPSec Remote Access to Corporate
LAN with Mode-Configuration Method
The following example demonstrates how to configure a router to be an IPSec VPN server
using mode-configuration method. The client could be any standard mode configuration
enabled IPSec VPN client.
In this example, the client needs to access the corporate private network 10.0.1.0/24 through
the VPN tunnel. The server has a pool of ip addresses from 20.1.1.100 through 20.1.1.150
to be allocated for mode configuration enabled VPN clients. The assigned IP address is used
by the VPN client as the source address in the inner IP header. The outer IP header carries
the dynamic IP address assigned by the Internet Service Provider as the source address. The
security requirements are as follows:
Example
• Phase 1: 3DES with SHA1, Mode Configuration
• Phase 2: IPSec ESP tunnel with AES256 and HMAC-SHA1
Avaya Secure Router 1000 Series Configuration Guide
Client Id
---------
Policy
Advanced
------
--------
sales
UserGrp
December 2010
159

Advertisement

Table of Contents
loading

Table of Contents