Corporate Headquarters


Step 3—Configuring Encryption and IPSec



Download 2,05 Mb.
Pdf ko'rish
bet69/135
Sana21.04.2022
Hajmi2,05 Mb.
#569058
1   ...   65   66   67   68   69   70   71   72   ...   135
Bog'liq
vpn cg

Step 3—Configuring Encryption and IPSec
Configuring the Cisco 7200 Series Router for Digital Certificate Interoperability
To configure your Cisco 7200 series router to use digital certificates as the authentication method, use 
the following steps, beginning in global configuration mode. This configuration assumes the use of the 
IOS default ISAKMP policy, which uses DES, SHA, RSA signatures, Diffie-Hellman group 1, and a 
lifetime of 86,400 seconds. Cisco recommends using 3DES. Refer to the 
“Creating IKE Policies” section 
on page 3-16
 for an ISAKMP configuration example which specifies 3DES as the encryption method.
Note
This example only configures the head-end Cisco 7200 series router. Additionally, each peer must be 
enrolled with a CA. This configuration example does not configure the CA. CA configuration 
instructions should be obtained from your CA vendor.
Verifying IKE Policies
To verify the configuration:

Enter the 
show crypto isakmp policy
EXEC command to see the default policy and any default 
values within configured policies.
hq-sanjose# 
show crypto isakmp policy
Protection suite priority 1
encryption algorithm:DES - Data Encryption Standard (56 bit keys)
hash algorithm:Secure Hash Standard
Command
Purpose
Step 1
hq-sanjose(config)#
crypto ca identity 
name
Declares a CA. The name should be the domain name of 
the CA. This command puts you into the ca-identity 
configuration mode.
Step 2
hq-sanjose(config)#
enrollment url 
url
Specifies the URL of the CA. (The URL should include 
any nonstandard cgi-bin script location.)
Step 3
hq-sanjose(config)#
enrollment mode ra
(Optional) Specifies RA mode if your CA system provides 
a registration authority (RA).
The Cisco IOS software automatically determines the 
mode—RA or non-RA; therefore, if RA mode is used, this 
subcommand is written to NVRAM during "write 
memory."

Download 2,05 Mb.

Do'stlaringiz bilan baham:
1   ...   65   66   67   68   69   70   71   72   ...   135




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish