HP ProCurve Secure Router 7203 dl Advanced Management And Configuration Manual page 388

Secure router
Hide thumbs Also See for ProCurve Secure Router 7203 dl:
Table of Contents

Advertisement

Contents
8-2
Certificates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-34
Mapping the Remote ID to an IKE Policy and Crypto
Map Entry . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-35
Defining Traffic Allowed over the VPN Tunnel . . . . . . . . . . . . . . . . . . 8-35
Restricting Specified Hosts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-36
Permitting Local and Remote Networks . . . . . . . . . . . . . . . . . . . . 8-37
Applying the ACL to a Crypto Map . . . . . . . . . . . . . . . . . . . . . . . . 8-38
Example Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-39
Enabling Router Traffic to Servers at a Remote VPN Site . . . . . 8-39
Configuring IPSec SA Parameters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-40
Transform Sets . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-40
Crypto Maps . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-42
Applying a Crypto Map to an Interface . . . . . . . . . . . . . . . . . . . . . . . . . 8-46
Mode Config (Required for Client-to-Site VPNs) . . . . . . . . . . . . . . . . 8-47
IKE Mode Config . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-47
Configuring an IKE Client Configuration Pool . . . . . . . . . . . . . . . 8-48
Applying the Pool to an IKE Policy . . . . . . . . . . . . . . . . . . . . . . . . 8-49
Using Extended Authentication (Xauth) (Optional) . . . . . . . . . . . . . . 8-49
Configuring an Xauth Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-50
Configuring an Xauth Host . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-53
Using Digital Certificates (Optional) . . . . . . . . . . . . . . . . . . . . . . . . . . 8-54
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-54
Obtaining Digital Certificates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-57
Managing Certificates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-61
Configuring the Transform Set . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-65
Configuring Crypto Maps for Manual IPSec . . . . . . . . . . . . . . . . . 8-67
Example Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-69
Monitoring a VPN . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-70

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve secure router 7102 dl

Table of Contents