Cisco Systems C7200 manual Creating Dynamic Crypto Maps 4

Page 5

Contents

Changing Existing Transforms

4 - 8

 

 

Transform Example

4 - 8

 

 

 

 

Configuring IPSec

4 - 8

 

 

 

 

 

Ensuring That Access Lists Are Compatible with IPSec

4 - 8

Setting Global Lifetimes for IPSec Security Associations

4 - 8

Creating Crypto Access Lists

4 - 10

 

 

 

Creating Crypto Map Entries

4 - 10

 

 

 

Creating Dynamic Crypto Maps 4 - 12

 

 

Applying Crypto Map Sets to Interfaces

4 - 14

 

Monitoring and Maintaining IPSec

4 - 14

 

 

Verifying IKE and IPSec Configurations

4 - 15

 

 

Verifying the Configuration 4 - 16

 

 

 

Configuration Examples

4 - 18

 

 

 

 

Configuring IKE Policies Example

4 - 18

 

 

 

Configuring IPSec Configuration Example

4 - 18

 

Basic IPSec Configuration Illustration

4 - 19

 

 

 

Router A Configuration

4 - 19

 

 

 

 

Router B Configuration

4 - 20

 

 

 

 

Troubleshooting Tips

4 - 21

 

 

 

 

 

Monitoring and Maintaining the VSA

4 - 23

 

 

 

Using Deny Policies in Access Lists

4 - 23

 

 

Configuration Guidelines and Restrictions

4 - 24

 

Monitor and Maintenance Commands

4 - 24

 

 

I N D E X

C7200 VSA (VPN Services Adapter) Installation and Configuration Guide

 

OL-9129-02

v

 

Image 5
Contents Text Part Number OL-9129-02 Corporate HeadquartersPage N T E N T S Preventing Electrostatic Discharge Damage 2 Creating Dynamic Crypto Maps 4 OL-9129-02 Audience PrefaceChapter Title Description ObjectivesOrganization Cisco.com Related DocumentationObtaining Documentation Product Documentation DVD Ordering Documentation Documentation FeedbackCisco Product Security Overview Product Alerts and Field Notices Reporting Security Problems in Cisco ProductsCisco Technical Support & Documentation Website Obtaining Technical AssistanceObtaining Additional Publications and Information Submitting a Service RequestDefinitions of Service Request Severity Xiv Data Encryption Overview OverviewVSA Overview VSA Module Front View Screws Handle Status LED lightThis section describes the VSA features, as listed in Table FeaturesFeature Description/Benefit Hardware RequiredPerformance Supported Standards, MIBs, and RFCsStandards MIBsEnabling/Disabling the VSA Command PurposeDisabling the VSA during Operation Enabling/Disabling SchemeLEDs Condition System is ConfiguredCommand Description of VSA Behavior See -2for the VSA connectors ConnectorsSlot Locations Cisco 7204VXR RouterCisco 7204VXR Router Front View Port adapter VSA in I/O controller slot Port adapter leverCisco 7206VXR Front View Cisco 7206VXR RouterHardware and Software Requirements Required Tools and EquipmentHardware Requirements Software RequirementsRestrictions PlatformOnline Insertion and Removal OIR Safety GuidelinesSafety Warnings Preventing Electrostatic Discharge Damage Electrical Equipment GuidelinesPreparing for Installation OL-9129-02 VSA circuit board is sensitive to ESD damage Handling the VSAThis section describes how to remove and install the VSA VSA Removal and InstallationRemoving and Installing the VSA VSA Removal and Installation OL-9129-02 Overview Configuration TasksConfiguring an IKE Policy Using the Exec Command InterpreterConfig-isakmp mode Key Management Protocol Isakmp policy configurationOptional Specifies the authentication method within an IKE Signatures as the authentication methodDisabling VSA Optional Configuring a Transform SetDefining a Transform Set Transform type Description Selecting Appropriate Transforms Crypto Transform Configuration ModeIPSec Protocols AH and ESP Ensuring That Access Lists Are Compatible with IPSec Configuring IPSecSetting Global Lifetimes for IPSec Security Associations Changing Existing TransformsStep Command Purpose Creating Crypto Map Entries Creating Crypto Access ListsAuthenticator keys if the transform set includes an Only one transform set can be specified when IKE isESP authenticator algorithm Exits crypto-map configuration mode and return toCreating Dynamic Crypto Maps Extended access list. This access list determines Optional Accesses list number or name of anIf this is configured, the data flow identity proposed For this crypto access listApplying Crypto Map Sets to Interfaces Monitoring and Maintaining IPSecRouter# show crypto isakmp policy Verifying IKE and IPSec ConfigurationsVerifying the Configuration Currentpeer 172.21.114.67 PERMIT, flags=originisacl Configuring IKE Policies Example Configuration ExamplesConfiguring IPSec Configuration Example This section provides the following configuration examplesCrypto map is applied to an interface Basic IPSec Configuration IllustrationRouter a Configuration Specify the parameters to be used during an IKE negotiation Router B ConfigurationTransform set defines how the traffic will be protected Router# show diag Troubleshooting TipsTunnel I/F Monitoring and Maintaining the VSA Using Deny Policies in Access ListsConfiguration Guidelines and Restrictions Monitor and Maintenance CommandsD E Set session-key command Set transform-set command Sa command, clear crypto Entries, creatingSet pfs command Handling VPN Acceleration Module see VAM 1 Features Handling Monitoring and maintaining 4 OverviewIN-4