HP ProCurve Secure Router 7203 dl Advanced Management And Configuration Manual page 416

Secure router
Hide thumbs Also See for ProCurve Secure Router 7203 dl:
Table of Contents

Advertisement

Virtual Private Networks
Configuring a VPN Using IPSec
8-30
stronger security parameters. The policy for the mobile clients would include
a higher-priority attribute policy for the preferred security parameters, but
also an attribute policy with lower security options.
Mobile Users
10.2.2.1
Site A Router
10.3.3.1
Site B Router
Figure 8-5. Example IKE Proposals
You would complete these steps:
1.
Create the IKE policy for initiating IKE phase 1 with routers at remote
sites.
ProCurve(config)# ip crypto
ProCurve(config)# crypto ike policy 1
ProCurve(config-ike)# peer 10.2.2.1
ProCurve(config-ike)# peer 10.3.3.1
ProCurve(config-ike)# respond main
2.
Configure the high-security IKE SA proposals in an attribute policy. The
same proposals must be configured on the remote routers.
ProCurve(config-ike)# attribute 10
ProCurve(config-ike-attribute)# authentication dss-sig
ProCurve(config-ike-attribute)# encryption 3des
ProCurve(config-ike-attribute)# hash sha
ProCurve(config-ike-attribute)# lifetime 240
ProCurve(config-ike-attribute)# group 2
3.
Create the IKE policy for responding to IKE phase 1 from mobile users.
The router cannot initiate IKE with mobile users. Leave the respond mode
at the default, anymode.
ProCurve(config-ike-attribute)# crypto ike policy 10
ProCurve(config-ike)# peer any
ProCurve(config-ike)# no initiate
IKE SA
Proposals for
mobile users
Internet
HQ Router
IKE SA
proposals for
routers

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve secure router 7102 dl

Table of Contents