5.4.1 VPN via Dialer Interface rtr1

XSR-1805-1#show running-config

!!

!Version 6.0.0.9, Built Dec 12 2003, 14:56:30

hostname XSR-1805-1

interface bri 0/1/0

isdn switch-type basic-net3 no shutdown

dialer pool-member 1 priority 0

access-list 101 permit

ip

20.20.20.0 0.0.0.255 10.10.10.0 0.0.0.255

access-list 101

permit

ip

any host 1.1.1.2

access-list 121

permit

ip

20.20.20.0 0.0.0.255 10.10.10.0 0.0.0.255

!

 

 

 

crypto isakmp proposal

ISDN

 

authentication pre-share

 

!

crypto isakmp peer 1.1.1.2 255.255.255.255 proposal ISDN

!

crypto ipsec transform-set isdntr esp-3des esp-md5-hmac set pfs group2

no set security-association lifetime kilobytes

!

crypto map myisdn 20

set transform-set isdntr match address 121

set peer 1.1.1.2

!

interface FastEthernet 1

ip address 20.20.20.1 255.255.255.0 no shutdown

!

interface Dialer1 crypto map myisdn dialer pool 1 dialer string 120 encapsulation ppp dialer-group 1

ip address 1.1.1.1 255.255.255.0 no shutdown

!

ip route 10.10.10.0 255.255.255.0 1.1.1.2

!

dialer-list 1 protocol ip list 101

!

end

XSR-1805-1(config)#aaa user 1.1.1.2

XSR-1805-1(config-aaa)#password XSR

XSR-1805-1#

Configuration Guide

Page 19 of 55

Page 19
Image 19
Enterasys Networks XSR-Series manual VPN via Dialer Interface rtr1, Dialer-list 1 protocol ip list