Documentos de Académico
Documentos de Profesional
Documentos de Cultura
Un tunel Ipsec trece prin 5 faze, dar nu toate acestea eu nevoie de configurare.
Pentru a configura site-to-site VPN folosind Cisco CLI este nevoie de urmatorii pasi.
To allow IKE Phase 1 negotiation, you must create an Internet Security Association and Key Management Protocol
(ISAKMP) policy and configure a peer association involving that ISAKMP policy.
Step 2: Configure the IPsec Transform Set and Lifetimes (IKE phase 2)The IPsec transform set is another
crypto configuration parameter that routers negotiate to form a security association. Routers will compare their
transform sets to the remote peer until they find a transform set that matches exactly.
R1(config)# crypto ipsec transform-set 50-set esp-aes 256 esp-sha-hmac ah-sha-hmac
R1(config)#mode tunnel
R1(cfg-crypto-trans)# exit
You can also change the IPsec security association lifetimes from its default which is 3600 seconds or 4,608,000
kilobytes, whichever comes first.
Usually, it is very important that the two lists be mirror images of each other. The source address in one list must be
the destination address in the other and vice versa.