Virtual Private Networks
Quick Start
Parameters
peer ID
peer's remote ID
preshared key (if using)
IKE policy number
initiate mode
attribute policy number for
IKE SA proposals
IKE authentication
method
IKE SA authentication
algorithm
10-88
Quick Start
This section provides the commands you must enter to quickly configure:
a site-to-site VPN
a client-to-site VPN
digital certificates
Only a minimal explanation is provided. If you need additional information
about any of these options, see "Contents" on page 10-1 to locate the section
and page number that contains the explanation you need.
Table 10-31. Quick Start Settings for a Site-to-Site VPN
Options
IP address (A.B.C.D)
• IP address (A.B.C.D)
• fully-qualified domain name
(FQDN)
• email address
• abstract syntax notation
distinguished name (ASN-
DN), for digital certificates
only
alphanumeric string
1 to 10,000
• main
• aggressive
• none
1 to 65,535
• preshared keys
• DSS digital certificate
• RSA digital certificates
• MD5
• SHA-1
Obtain Setting From
remote router's public IP
address
remote router
match peer
—
peer's respond mode—
however, at least one side
must be able to initiate
—
match peer
match peer
Your Setting