!
! Activate the crypto-list and the access control list on the public interface
!
interface FastEthernet 10/2
ip crypto-group 901
ip access-group 301 in
ip access-group 302 out
exit
Check-List for Configuring site-to-site IPSec VPN
Use the following table to gather the information for simple G250 and G350 site-to-site IPSec
VPN.
Table 66: Checklist for configuring site-to-site IPSec VPN
Parameter
1. VPN License
2. Type of connection to the ISP
3. VPN Interface
4. VPN Local IP Address
a. Type
5. Coordinating with the VPN Remote peer.
a. VPN IKE (Control) Phase 1 Parameters
Check-List for Configuring site-to-site IPSec VPN
Possible values
You require the serial number to
obtain the VPN license
ADSL
●
Cable Modem
●
Fast Ethernet 10/2
●
Serial port X/Y
●
Static
●
- If static, provide:
IP Address
Mask
Next-hop Router
Dynamic (DHCP/PPPoE)
●
Actual value
1 of 3
Issue 3 February 2007
527