13.07.2015 Views

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring a site-to-site IPSec VPNImportant:! Important:You must define at least one transform-set.<strong>G350</strong>-001# crypto ipsec transform-set ts1 esp-3des esp-md5-hmac<strong>G350</strong>-001(config-transform:ts1)#2. Configure <strong>the</strong> following transform-set parameters:●●●set pfs: specifies whe<strong>the</strong>r each IKE phase 2 negotiation will employ PFS (PerfectForward Secrecy), and if yes – which Diffie-Hellman group to employ. PFS ensures thateven if someone were to discover <strong>the</strong> long-term secret(s), <strong>the</strong> attacker would not be ableto recover <strong>the</strong> session keys, both past and present. In addition, <strong>the</strong> discovery <strong>of</strong> asession key compromises nei<strong>the</strong>r <strong>the</strong> long-term secrets nor <strong>the</strong> o<strong>the</strong>r session keys. Thedefault setting is no set pfs.set security-association lifetime seconds: <strong>the</strong> security association lifetimein seconds using <strong>the</strong> CLI commandset security-association lifetime kilobytes: <strong>the</strong> security associationlifetime in kilobytes<strong>G350</strong>-001001(config-transform:ts1ts1)# set pfs group2Done!<strong>G350</strong>-001(config-transform:ts1)# set security-association lifetime seconds7200Done!<strong>G350</strong>-001(config-transform:ts1)# set security-association lifetimekilobytes 2684354563. Exit <strong>the</strong> crypto transform-set context using <strong>the</strong> exit CLI command.<strong>G350</strong>-001(config-transform:ts1)# exit<strong>G350</strong>-001#Configuring ISAKMP peer informationISAKMP peer information defines <strong>the</strong> remote peer identification, <strong>the</strong> pre-shared key used forpeer au<strong>the</strong>ntication, and <strong>the</strong> ISAKMP policy to be used for IKE phase 1 negotiations between<strong>the</strong> peers.Important:Note:! Important:It is mandatory to define at least one ISAKMP peer.Note:You can define up to 50 ISAKMP peers.Issue 3 January 2005 211

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!