13.07.2015 Views

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

FIPS<strong>G350</strong>-N(super)# ip crypto-list 901<strong>G350</strong>-N(crypto-list-901)# local-address 10.0.0.1Done!<strong>G350</strong>-N(crypto-list-901)# ip-rule 10Done!<strong>G350</strong>-N(crypto-list-901)# protect crypto map 1Done!<strong>G350</strong>-N(crypto-list-901)# source-ip anyDonw!<strong>G350</strong>-N(crypto-list-901)# destination-ip anyDone!exitexit<strong>G350</strong>-N(super)# ip crypto-list 902<strong>G350</strong>-N(crypto-list-902)# local-address 1.0.0.1Done!<strong>G350</strong>-N(crypto-list-902)# ip-rule 10Done!<strong>G350</strong>-N(crypto-list-902)# protect crypto map 2Done!<strong>G350</strong>-N(crypto-list-902)# source-ip anyDone!<strong>G350</strong>-N(crypto-list-902)# destination-ip anyDone!exitNote:Note:TELNET, FTP, TFTP, and SNMP are always ESP with TDES- or AES- encrypted.Null encryption or AH are NOT allowed for such flows.37. Activate <strong>the</strong> crypto-lists on <strong>the</strong> inbound direction <strong>of</strong> all cipher-text interfaces. For flows thatneed to be encrypted even if directed to clear-text interfaces, apply crypto lists to allinterfaces.●Use <strong>the</strong> ip crypto-list list-id command in <strong>the</strong> interface context.<strong>G350</strong>-N(super)# interface serial 2/1:1<strong>G350</strong>-N(if: serial 2/1)# ip crypto-group 902Done!<strong>G350</strong>-N(if: serial 2/1)# exit<strong>G350</strong>-N(super)# interface FastE<strong>the</strong>rnet 10/2<strong>G350</strong>-N(if:fastE<strong>the</strong>rnet 10/2)# ip crypto-group 901Done!<strong>G350</strong>-N(if:fastE<strong>the</strong>rnet 10/2)# exit38. Save <strong>the</strong> running config to <strong>the</strong> startup config.● Use <strong>the</strong> copy running-config startup-config command twice to ensure thatconfiguration primary and backup both are being updated with approved modeconfiguration.39. Re-connect network interfaces.318 <strong>Administration</strong> <strong>of</strong> <strong>the</strong> <strong>Avaya</strong> <strong>G350</strong> <strong>Media</strong> <strong>Gateway</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!