Corporate Headquarters


Step 4 hq-sanjose(config-crypto-map)# set peer



Download 2,05 Mb.
Pdf ko'rish
bet80/135
Sana21.04.2022
Hajmi2,05 Mb.
#569058
1   ...   76   77   78   79   80   81   82   83   ...   135
Bog'liq
vpn cg

Step 4
hq-sanjose(config-crypto-map)#
set peer
{
hostname

ip-address
}
(Optional) Specifies a remote IPSec peer. Repeat for 
multiple remote peers.
This is rarely configured in dynamic crypto map entries. 
Dynamic crypto map entries are often used for unknown 
remote peers.
Step 5
hq-sanjose(config-crypto-map)#
set 
security-association lifetime seconds
seconds
and/or
set security-association lifetime kilobytes
kilobytes
(Optional) If you want the security associations for this 
crypto map to be negotiated using shorter IPSec security 
association lifetimes than the globally specified lifetimes, 
specify a key lifetime for the crypto map entry.
Step 6
hq-sanjose(config-crypto-map)#
exit
hq-sanjose(config)#
Exit back to global configuration mode.
Command
Purpose


3-27
Cisco IOS VPN Configuration Guide
OL-8336-01
Chapter 3 Site-to-Site and Extranet VPN Business Scenarios
Step 3—Configuring Encryption and IPSec
hq-sanjose# 
show crypto map
Crypto Map: “s4second” idb: Serial2/0 local address: 172.16.2.2
Crypto Map “s4second” 2 ipsec-isakmp
Peer = 172.23.2.7
Extended IP access list 111
access-list 111 permit ip 
source: addr = 10.2.2.2/255.255.255.0
dest: addr = 10.1.5.3/255.255.255.0S
Current peer: 172.23.2.7
Security-association lifetime: 4608000 kilobytes/3600 seconds
PFS (Y/N): N
Transform sets={proposal4,}
-Display text omitted-
Tip
If you have trouble, make sure you are using the correct IP addresses.
Applying Crypto Maps to Interfaces
You need to apply a crypto map set to each interface through which IPSec traffic will flow. Applying the 
crypto map set to an interface instructs the router to evaluate all the interface traffic against the crypto 
map set, and to use the specified policy during connection or SA negotiation on behalf of traffic to be 
protected by crypto.
To apply a crypto map set to an interface, complete the following steps starting in global configuration 
mode:

Download 2,05 Mb.

Do'stlaringiz bilan baham:
1   ...   76   77   78   79   80   81   82   83   ...   135




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish