crypto ipsec
crypto map
crypto map map name map number
ØMatch address – specify the extended access list for crypto map
Ø
Øset peer [hostname ip address] – specify the IPsec peer in a crypto map
Øset session key [inbound outbound] [ah esp] spi [ciper]
-inbound – set inbound session key
-outbound- set outbound session key
-ah – set AH protocol for Ipsec session key
-ciper - Indicates that the key is to be used with the ESP encryption .
- authenticator – (optional) Indicates that the key is to be used with the ESP encryption crypto map map name map number
Ømatch address – specify the extended access list for crypto map
Øset peer [hostname ip address] – specify the IPsec peer in a crypto map
Øset
Øset pfs [group 1 group 2] – specify the pfs setting. Group 1 is
Øset
-level
-lifetime [seconds kilobytes] - override the global lifetime value that is used when negotiating IPSec security.
crypto map
48