Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support Administration of the Avaya G350 Media Gateway - Avaya Support

downloads.avaya.com
from downloads.avaya.com More from this publisher
13.07.2015 Views

Configuring IPSec VPN9. Exit crypto-list context using the exit CLI command.G350-001(Crypto 901)# exitG350-001#Configuring interfacesA crypto-list is activated on an interface. G-350 can have multiple crypto-lists activated ondifferent interfaces.To configure an interface:1. Enter interface context using the interface CLI command.G350-001# interface Serial 2/1G350-001(if: Serial 2/1)#2. Configure the following interface parameters:●ip crypto-group: the crypto-list to be activated on this interfaceImportant:●●! Important:ip crypto-group is a mandatory parameter.crypto ipsec minimal pmtu: This command is intended for advanced users only. Itsets the minimal PMTU value which can be applied to an SA when the G350 participatesin Path MTU Discovery (PMTUD) for the tunnel pertaining to that SA.crypto ipsec df-bit copy: This command is intended for advanced users only. Itsets the Don’t-Fragment bit to either clear or copy mode:●copy – the DF bit of the encapsulated packet is copied from the original packet, andPath MTU Discovery (PMTUD) is maintained for the IPSec tunnel.● clear – the DF bit of the encapsulated packet is never set, and PMTUD is notmaintained for the IPSec tunnel.Packets traversing an IPSec tunnel are pre-fragmented according to the MTU of the SA,regardless of their DF bit. In case packets are fragmented, the DF bit is copied to everyfragment of the original packet.G350-001(if: Serial 2/1)# ip crypto-group 901Done!G350-001(if: Serial 2/1)# crypto ipsec minimal pmtu 500Done!G350-001(if: Serial 2/1)# crypto ipsec df-bit copyDone!216 Administration of the Avaya G350 Media Gateway

Configuring a site-to-site IPSec VPN3. Exit the interface context using the exit CLI command.G350-001(if: Serial 2/1)# exitG350-001#Deactivating crypto lists to modify IPSec VPN parametersMost IPSec VPN parameters cannot be modified if they are linked to an active crypto list. Tomodify a parameter linked to an active crypto list, you must first deactivate the list using theno ip crypto-group CLI command in the context of the interface on which the crypto list isactivated.Note:Note: If the crypto list is activated on more than one interface, deactivate the crypto listfor each of the interfaces on which it is activated.For example:G350-001# interface Serial 2/1G350-001(if: Serial 2/1)# no ip crypto-groupDone!After modifying IPSec VPN parameters as desired, re-activate the crypto list on the interfaceusing the ip crypto-group crypto-list-id CLI command. For example:G350-001# interface Serial 2/1G350-001(if: Serial 2/1)# ip crypto-group 901Done!Issue 3 January 2005 217

Configuring a site-to-site IPSec VPN3. Exit <strong>the</strong> interface context using <strong>the</strong> exit CLI command.<strong>G350</strong>-001(if: Serial 2/1)# exit<strong>G350</strong>-001#Deactivating crypto lists to modify IPSec VPN parametersMost IPSec VPN parameters cannot be modified if <strong>the</strong>y are linked to an active crypto list. Tomodify a parameter linked to an active crypto list, you must first deactivate <strong>the</strong> list using <strong>the</strong>no ip crypto-group CLI command in <strong>the</strong> context <strong>of</strong> <strong>the</strong> interface on which <strong>the</strong> crypto list isactivated.Note:Note: If <strong>the</strong> crypto list is activated on more than one interface, deactivate <strong>the</strong> crypto listfor each <strong>of</strong> <strong>the</strong> interfaces on which it is activated.For example:<strong>G350</strong>-001# interface Serial 2/1<strong>G350</strong>-001(if: Serial 2/1)# no ip crypto-groupDone!After modifying IPSec VPN parameters as desired, re-activate <strong>the</strong> crypto list on <strong>the</strong> interfaceusing <strong>the</strong> ip crypto-group crypto-list-id CLI command. For example:<strong>G350</strong>-001# interface Serial 2/1<strong>G350</strong>-001(if: Serial 2/1)# ip crypto-group 901Done!Issue 3 January 2005 217

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!