Ipsec Vpn Configuration Overview; Coordinating With The Vpn Peer - Avaya G250 Administration

Media gateways
Hide thumbs Also See for G250:
Table of Contents

Advertisement

IPSec VPN configuration overview

To configure a site-to-site IPSec VPN, two devices (the G250/G350 and a peer Gateway) must
be configured symmetrically.
In some cases, you may wish to configure global VPN parameters (see
parameters on page
Note:
In the following sections, all IPSec VPN parameters that you must configure are
Note:
indicated as mandatory parameters. Non-mandatory VPN parameters have default
values that are used unless otherwise set. Thus for example, although it is mandatory
to define at least one ISAKMP policy, it is not mandatory to set the values for that
ISAKMP policy since the G250/G350 contains default ISAKMP policy settings.

Coordinating with the VPN peer

Before commencing IPSec VPN configuration, you must resolve jointly with your VPN peer the
basic parameters so that IPSec VPN can be set up symmetrically in the two peers. If the IPSec
VPN configuration in the two peers does not match, no VPN is created.
Note:
If you will be defining a peer-group which maintains a list of redundant peers,
Note:
each of the peers in the group must be configured to match the G250/G350.
The basic parameters include:
The IKE phase 1 parameters (as defined in the ISAKMP policy, see
policies
on page 456)
The IKE phase 2 parameters (as defined in the transform-set, see
transform-sets
The ISAKMP peer parameters (see
Which packets should be secured (as defined in the crypto-list, see
crypto-lists
The peer addresses. For each peer, the local address entered in the crypto-list (see
Configuring crypto-lists
peer (see
NAT Traversal, if your installation includes one or more NAT devices between the local and
remote VPN peers. See
See
IPSec VPN logging
both peers so as to pinpoint the problem in case of a mismatch between the two peers.
468).
on page 457)
on page 464)
on page 464) should match the ISAKMP peer address in the other
Configuring ISAKMP peer information
Configuring global parameters on page
on page 472 for information on how to view IPSec VPN configuration in
Configuring a site-to-site IPSec VPN
Configuring ISAKMP peer information
on page 458).
Configuring global
Configuring ISAKMP
Configuring
on page 458).
Configuring
468.
Issue 3 February 2007
455

Advertisement

Table of Contents
loading

This manual is also suitable for:

G350

Table of Contents