SROS Command Line Interface Reference Guide

Global Configuration Mode Command Set

 

 

sets will be used to encrypt and/or authenticate the traffic on that VPN tunnel. It also specifies the lifetime of all created IPSec Security Associations.

(config)#crypto map corporate_vpn 1 ipsec-ike (config-crypto-map)#match address corporate_traffic (config-crypto-map)#set peer 63.105.15.129 (config-crypto-map)#set transform-set highly_secure (config-crypto-map)#set security-association lifetime kilobytes 8000 (config-crypto-map)#set security-association lifetime seconds 28800 (config-crypto-map)#no set pfs

Step 9:

Configure public interface. This process includes configuring the IP address for the interface and applying the appropriate crypto map to the interface. Crypto maps are applied to the interface on which encrypted traffic will be transmitted.

(config)#interface ppp 1

(config-ppp 1)#ip address 63.97.45.57 255.255.255.248 (config-ppp 1)#crypto map corporate_vpn (config-ppp 1)#no shutdown

Step 10:

Configure private interface to allow all traffic destined for the VPN tunnel to be routed to the appropriate gateway.

(config)#interface ethernet 0/1

(config-eth 0/1)#ip address 10.10.10.254 255.255.255.0

(config-eth 0/1)#no shutdown (config-eth 0/1)#exit

5991-2114

© Copyright 2005 Hewlett-Packard Development Company, L.P.

226

Page 226
Image 226
HP 7000 dl Router manual Config-eth 0/1#no shutdown config-eth 0/1#exit