Chapter 4 Configuring the VSA
Basic IPSec Configuration Illustration
The crypto map is applied to an interface:
interface Serial0 ip address 10.0.0.2
crypto map toRemoteSite
Note In this example, IKE must be enabled.
Basic IPSec Configuration Illustration
The following is an example of an IPSec configuration in which the security associations are established through IKE. In this example, an access list is used to restrict the packets that are encrypted and decrypted. In this example, all packets going from IP address 10.0.0.2 to IP address 10.2.2.2 are encrypted and decrypted and all packets going from IP address 10.2.2.2 to IP address 10.0.0.2 are encrypted and decrypted. Also, one IKE policy is created.
Figure 4-1 Basic IPSec Configuration
Only packets from 10.0.0.2 to 10.2.2.2 are encrypted and authenticated across the network.
Clear text | Encrypted text |
10.0.0.2 |
|
10.0.0.3 | 10.2.2.3 |
Router A | Router B |
10.0.0.1
All other packets are not encrypted
Clear text
Clear text
10.2.2.2
10.2.2.1
29728
Router A Configuration
Specify the parameters to be used during an IKE negotiation:
Update to 3DES/AES
crypto isakmp policy 15 encryption des
hash md5
authentication
lifetime 5000
crypto isakmp key 1234567890 address 10.2.2.3 crypto isakmp identity address
C7200 VSA (VPN Services Adapter) Installation and Configuration Guide
|
| ||
|
|