VPN Site-to-Site Sample Configuration

Create a Transform Set

The following transform-set specifies the specified encryption/data integrity choices, 768-bitDiffie-Hellman, and an SA lifetime expressed in kilobytes. The SA seconds lifetime value is disabled. Some commands are abbreviated.

XSR(config)#crypto ipsec tra esp-3des-sha esp-3des esp-sha-hmac

XSR(cfg-crypto-tran)#set pfs group1

XSR(cfg-crypto-tran)#set sec lifetime kilobytes 100000

XSR(cfg-crypto-tran)#no set sec lifetime seconds

Configure Crypto Maps

The following IKE policy crypto maps are each linked to the earlier added transform-set with matching ACLs and are set by default for the more stringent tunnel mode. Maps 91 and 92 match the remote XSRs and map 90 correlates with the ANG. Crypto map statements render the associated ACLs bi-directional.

XSR(config)#crypto map acme 92

XSR(config-crypto-m)#set transform-set esp-3des-sha

XSR(config-crypto-m)#match address 192

XSR(config-crypto-m)#set peer 112.16.244.5

XSR(config)#crypto map acme 91

XSR(config-crypto-m)#set transform-set esp-3des-sha

XSR(config-crypto-m)#match address 191

XSR(config-crypto-m)#set peer 112.16.244.7

XSR(config)#crypto map acme 90

XSR(config-crypto-m)#set transform-set esp-3des-sha

XSR(config-crypto-m)#match address 190

XSR(config-crypto-m)#set peer 112.16.244.9

Configuring VPN at Interface Mode and Setting Up RIP

The following commands configure the LAN physical ports as follows: GigabitEthernet port 1 is designated Internal LAN, with the specified IP address/subnet as the designated network. GigabitEthernet port 2 is named VPN Cloud, assigned crypto map acme with associated ACLs, and directed not to transmit or receive RIP updates. Also, RIP routing and four IP routes are configured as well as a VPN interface for AAA service.

XSR(config)#interface gigabitethernet 1

XSR(config-if<G1>)#description “Internal LAN”

XSR(config-if<G1>)#no shutdown

XSR(config-if<G1>)#ip address 112.16.1.221 255.255.255.0

XSR(config)#interface gigabitethernet 2

XSR(config-if<G2>)#crypto map acme

XSR(config-if<G2>)#description “VPN Cloud”

XSR(config-if<G2>)#no shutdown

XSR(config-if<G2>)#ip access-group 101 in

XSR(config-if<G2>)#ip access-group 101 out

XSR(config-if<G2>)#ip address 112.16.244.10 255.255.255.0

3-28 Software Configuration

Page 72
Image 72
Enterasys Networks XSR-3020 manual Create a Transform Set, Configure Crypto Maps

XSR-3020 specifications

Enterasys Networks XSR-3020 is a sophisticated Layer 2 and Layer 3 switch designed to meet the demands of modern networking environments. Known for its robust performance and versatility, the XSR-3020 is an ideal solution for enterprises that require high efficiency, comprehensive security, and network reliability.

This switch supports a variety of advanced technologies, making it suitable for both data center and edge deployments. One of its standout features is its scalability. The XSR-3020 can accommodate growing network demands by allowing for easy integration of additional modules. This capacity for expansion ensures that organizations can adapt their networks without the need for complete hardware replacements.

The XSR-3020 offers high-speed connectivity through its multiple gigabit Ethernet ports, providing up to 48 10/100/1000BASE-T ports in a single chassis. This high-density design optimizes the physical space and ensures that organizations can connect numerous devices simultaneously without sacrificing performance. Additionally, it supports Power over Ethernet (PoE), allowing users to power network devices, such as IP cameras and access points, directly through the switch. This feature streamlines installations and reduces the clutter of electrical wiring.

Security is a critical consideration in today’s network landscape, and the XSR-3020 addresses this need with robust security features. It incorporates advanced access control capabilities, enabling administrators to segment traffic and enforce policies effectively. The switch also supports 802.1X authentication, ensuring that only authorized devices can connect to the network.

In terms of management, the XSR-3020 is designed to simplify operations through its user-friendly interface and extensive support for management protocols. It offers native support for Simple Network Management Protocol (SNMP) and can be easily integrated with various network management systems, allowing for efficient monitoring and troubleshooting.

Another key characteristic of the XSR-3020 is its reliability. With features such as redundant power supplies and fans, the switch ensures high availability, minimizing downtime for critical applications. It is also built to withstand harsh conditions, making it suitable for diverse environments.

Overall, the Enterasys Networks XSR-3020 combines high performance, scalability, and security, making it an excellent choice for organizations looking to enhance their network infrastructure. Its comprehensive set of features positions it as a reliable backbone for any modern enterprise network, ensuring that businesses can operate efficiently and securely.