Cisco Systems C819GUK9 manual The example specifies 168-bit data encryption, standard SHA-1, 13-4

Models: C819GUK9

1 196
Download 196 pages 51.42 Kb
Page 152
Image 152
The example specifies 168-bit data encryption

Chapter 13 Configuring a VPN Using Easy VPN and an IPSec Tunnel

Configuration Tasks

6.lifetime seconds

7.exit

DETAILED STEPS

 

 

 

 

Command or Action

Purpose

 

 

 

Step 1

 

 

 

 

 

crypto isakmp policy priority

Creates an IKE policy that is used during IKE

 

 

 

 

Example:

negotiation. The priority is a number from 1 to

 

 

 

 

10000, with 1 being the highest.

 

 

 

 

Router(config)# crypto isakmp policy 1

Also enters the Internet Security Association Key

 

 

 

 

Router(config-isakmp)#

 

 

 

 

and Management Protocol (ISAKMP) policy

 

 

 

 

 

 

 

 

 

 

configuration mode.

 

 

 

Step 2

 

 

 

 

 

encryption {des 3des aes aes 192

Specifies the encryption algorithm used in the IKE

 

 

 

 

aes 256}

policy.

 

 

 

 

Example:

The example specifies 168-bit data encryption

 

 

 

 

standard (DES).

 

 

 

 

Router(config-isakmp)# encryption 3des

 

 

 

 

 

 

 

 

 

 

Router(config-isakmp)#

 

 

 

 

 

Step 3

 

 

 

 

 

hash {md5 sha}

Specifies the hash algorithm used in the IKE

 

 

 

 

Example:

policy.

 

 

 

 

The example specifies the Message Digest 5

 

 

 

 

Router(config-isakmp)# hash md5

 

 

 

 

(MD5) algorithm. The default is Secure Hash

 

 

 

 

Router(config-isakmp)#

 

 

 

 

standard (SHA-1).

 

 

 

 

 

 

 

 

Step 4

 

 

 

 

 

authentication {rsa-sig rsa-encr

Specifies the authentication method used in the

 

 

 

 

pre-share}

IKE policy.

 

 

 

 

Example:

The example specifies a pre-shared key.

 

 

 

 

 

 

 

 

 

 

Router(config-isakmp)# authentication

 

 

 

 

 

 

pre-share

 

 

 

 

 

 

Router(config-isakmp)#

 

 

 

 

 

Step 5

 

 

 

 

 

group {1 2 5}

Specifies the Diffie-Hellman group to be used in

 

 

 

 

Example:

an IKE policy.

 

 

 

 

 

 

 

 

 

 

Router(config-isakmp)# group 2

 

 

 

 

 

 

Router(config-isakmp)#

 

 

 

 

 

Step 6

 

 

 

 

 

lifetime seconds

Specifies the lifetime, 60 to 86400 seconds, for an

 

 

 

 

Example:

IKE security association (SA).

 

 

 

 

 

 

 

 

 

 

Router(config-isakmp)# lifetime 480

 

 

 

 

 

 

Router(config-isakmp)#

 

 

 

 

 

Step 7

 

 

 

 

 

exit

Exits IKE policy configuration mode and enters

 

 

 

 

Example:

global configuration mode.

 

 

 

 

 

 

 

 

 

 

Router(config-isakmp)# exit

 

 

 

 

 

 

Router(config)#

 

 

 

 

 

 

 

 

 

 

 

 

Cisco 819 Integrated Services Routers Software Configuration Guide

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

13-4

 

 

 

OL-23590-02

 

 

 

 

 

 

Page 152
Image 152
Cisco Systems C819GUK9 The example specifies 168-bit data encryption, standard SHA-1, IKE security association SA, 13-4