D-Link DI-1750 Reference Manual page 379

Hide thumbs Also See for DI-1750:
Table of Contents

Advertisement

5. Creating Policies
You can create multiple IKE policies, each with a different combination of parameter values. For each
policy that you create, you assign a unique priority (1 through 10,000, with 1 being the highest priority).
You can configure multiple policies on each peer—but at least one of these policies must contain
exactly the same encryption, hash, authentication, and Diffie-Hellman parameter values as one of the
policies on the remote peer.
If you do not configure any policies, your router will use the default policy, which is always set to the
lowest priority, and which contains each parameter's default value.
To configure a policy, use the following commands starting in global configuration mode:
Command
crypto
isakmp
priority
encryption {des|3des}
hash {sha | md5}
authentication
{ pre-share|rsa-sig|rsa-e
ncr}
group {1 | 2}
lifetime seconds
Exit
show
crypto
policy
[DEFAULT@Router /config/]#crypto
Key Word:
U(undo)
D(default)
......
(02)isakmp
(03)map
Please Input the code of command to be excute(0-3): 2
Key Word:
Q(quit)
(00)key
(01)policy
Please Input the code of command to be excute(0-1): 1
Key Word:
Q(quit)
(00)<1-10000>
Please Input the code of command to be excute(0-0): 0
Please input a digital number:10 (Input Priority Value)
Will you excute it? (Y/N):y
Key Word:
Q(quit)
......
(06)encryption
(07)english
......
Please Input the code of command to be excute(0-22): 6
Key Word:
U(undo)
D(default)
(00)des
(01)3des
Model Name
Create IKE policy (Each policy is uniquely identified by the priority
policy
number you assign.) (This command puts you into the config-isakmp
command mode.)
Specify the encryption algorithm.
Specify the hash algorithm.
Specify the authentication method.
Specify the Diffie-Hellman group.
Specifiy the security association's lifetime.
Exit the config-isakmp command mode.
(Optional) View all existing IKE policies. (Use this command in EXEC
isakmp
mode.)
Q(quit)
Configure ISAKMP policy
Enter a crypto map
Set pre-shared key for remote peer
Set policy for an ISAKMP protection suite
Priority of protection suite
Set encryption algorithm for protection suite
help message in English
Q(quit)
Data Encryption Standard
Triple Data Encryption Standard
- 377 -
Purpose

Advertisement

Table of Contents
loading

This manual is also suitable for:

Di-2621Di-2630Di-3660

Table of Contents