SmartWare Software Configuration Guide
Bytes (processed/lifetime) Seconds (age/lifetime)
IN
MANUAL
200.200.200.1
3622/unlimited
OUT MANUAL
200.200.200.1
2857/unlimited
Sample configurations
The following sample configurations establish IPsec connections between a SmartNode and a Cisco Router. To
interconnect two SmartNodes instead, derive the configuration for the second SmartNode by doing the follow-
ing modifications:
•
swap 'inbound' and 'outbound' settings
•
adjust the 'peer' setting
•
swap the private networks in the ACL profiles
•
adjust the IP addresses of the LAN and WAN interfaces
•
adjust the route for the remote network
IPsec tunnel, DES encryption
SmartNode configuration
profile ipsec-transform DES
esp-encryption des-cbc 64
profile ipsec-policy-manual VPN_DES
use profile ipsec-transform DES
session-key inbound esp-encryption 1234567890ABCDEF
session-key outbound esp-encryption FEDCBA0987654321
spi inbound esp 1111
spi outbound esp 2222
peer 200.200.200.1
mode tunnel
profile acl VPN_Out
permit ip 192.168.1.0 0.0.0.255 172.16.0.0 0.0.255.255 ipsec-policy VPN_DES
permit ip any any
profile acl VPN_In
permit esp any any
permit ah any any
permit ip 172.16.0.0 0.0.255.255 192.168.1.0 0.0.0.255
deny ip any any
context ip router
interface LAN
ipaddress 192.168.1.1 255.255.255.0
Sample configurations
ToBerne
Tunnel
-
1111
19047/unlimited
ToBerne
Tunnel
-
2222
19047/unlimited
no
-
-
no
-
-
22 • VPN configuration
AES-CBC 128
AES-CBC 128
271
Need help?
Do you have a question about the SmartNode Series and is the answer not in the manual?