Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support Administration of the Avaya G350 Media Gateway - Avaya Support

downloads.avaya.com
from downloads.avaya.com More from this publisher
13.07.2015 Views

Configuring IPSec VPNTo configure peer information:1. Enter the ISAKMP peer context and define an ISAKMP peer by its address, using thecrypto isakmp peer CLI command.G350-001# crypto isakmp peer address 149.49.70.1G350-001(config-peer:149.49.70.1)#2. Enter a description for the peer.G350-001(config-peer:149.49.70.1)# description "New York office"Done!3. Specify an ISAKMP policy to be used with the peer, using the isakmp policy CLIcommand.Important:! Important:isakmp policy is a mandatory parameter.G350-001(config-peer:149.49.70.1)# isakmp-policy 1Done!4. Enter the preshared key for peer authentication using the pre-shared-key CLIcommand.Important:! Important:pre-shared-key is a mandatory parameter.G350-001(config-peer:149.49.70.1)# pre-shared-key GNpi1odGNBrB5z4GJLDone!OrObtain a suggested key from the gateway using the crypto isakmp suggest-key CLIcommand and then enter it using the pre-shared-key CLI command. Note that you mustexit the ISAKMP peer context before using the crypto isakmp suggest-keycommand, and re-enter ISAKMP peer context to use the pre-shared-key command.The suggested key-length can vary from 8-127 characters, and the default is 32 characters.G350-001(config-peer:149.49.70.1)# exitG350-001# crypto isakmp suggest-key 24The suggest key: yjsYIz9ikcwaq0FUPTF3CIrwG350-001# crypto isakmp peer address 149.49.70.1G350-001(config-peer:149.49.70.1) pre-shared-key yjsYIz9ikcwaq0FUPTF3CIrwDone!212 Administration of the Avaya G350 Media Gateway

Configuring a site-to-site IPSec VPN5. Exit the peer context using the exit CLI command.G350-001(config-peer:149.49.70.1)# exitG350-001#Configuring crypto mapsA crypto map points to a transform-set and to a peer (which in turn points to an ISAKMP policy).These components define how to secure the traffic that matches the ip-rule that points to thiscrypto map.Important:! Important:It is mandatory to create at least one crypto map.Note:Note: You can configure up to 50 crypto maps.To configure a crypto map:1. Enter crypto map context and create a crypto map by using the crypto map CLIcommand.G350-001# crypto map 1G350-001(config-crypto:1)#2. Configure the following crypto map parameters:●●●●description: the description of the crypto mapset peer: the remote peerset transform set: the specific transform-set to which this crypto map pointsset dscp: the static DSCP value in the DS field of the tunneled packet. The defaultsetting is no set dscp, which specifies that the DSCP is copied from the DS field of theoriginal packet.Important:! Important:set peer and set transform set are mandatory parameters.G350-001(config-crypto:1)# description "vpn lincroft branch"Done!G350-001(config-crypto:1)# set peer 149.49.60.60Done!G350-001(config-crypto:1)# set transform-set ts1Done!G350-001(config-crypto:1)# set dscp 38Done!Issue 3 January 2005 213

Configuring IPSec VPNTo configure peer information:1. Enter <strong>the</strong> ISAKMP peer context and define an ISAKMP peer by its address, using <strong>the</strong>crypto isakmp peer CLI command.<strong>G350</strong>-001# crypto isakmp peer address 149.49.70.1<strong>G350</strong>-001(config-peer:149.49.70.1)#2. Enter a description for <strong>the</strong> peer.<strong>G350</strong>-001(config-peer:149.49.70.1)# description "New York <strong>of</strong>fice"Done!3. Specify an ISAKMP policy to be used with <strong>the</strong> peer, using <strong>the</strong> isakmp policy CLIcommand.Important:! Important:isakmp policy is a mandatory parameter.<strong>G350</strong>-001(config-peer:149.49.70.1)# isakmp-policy 1Done!4. Enter <strong>the</strong> preshared key for peer au<strong>the</strong>ntication using <strong>the</strong> pre-shared-key CLIcommand.Important:! Important:pre-shared-key is a mandatory parameter.<strong>G350</strong>-001(config-peer:149.49.70.1)# pre-shared-key GNpi1odGNBrB5z4GJLDone!OrObtain a suggested key from <strong>the</strong> gateway using <strong>the</strong> crypto isakmp suggest-key CLIcommand and <strong>the</strong>n enter it using <strong>the</strong> pre-shared-key CLI command. Note that you mustexit <strong>the</strong> ISAKMP peer context before using <strong>the</strong> crypto isakmp suggest-keycommand, and re-enter ISAKMP peer context to use <strong>the</strong> pre-shared-key command.The suggested key-length can vary from 8-127 characters, and <strong>the</strong> default is 32 characters.<strong>G350</strong>-001(config-peer:149.49.70.1)# exit<strong>G350</strong>-001# crypto isakmp suggest-key 24The suggest key: yjsYIz9ikcwaq0FUPTF3CIrw<strong>G350</strong>-001# crypto isakmp peer address 149.49.70.1<strong>G350</strong>-001(config-peer:149.49.70.1) pre-shared-key yjsYIz9ikcwaq0FUPTF3CIrwDone!212 <strong>Administration</strong> <strong>of</strong> <strong>the</strong> <strong>Avaya</strong> <strong>G350</strong> <strong>Media</strong> <strong>Gateway</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!