IPsec Tunnel Interface
Except on the first page, right running head:
Heading1 or Heading1NewPage text (automatic)
803
Alcatel-Lucent
Beta
Beta
CLI Configuration Guide
IP
SEC
T
UNNEL
I
NTERFACE
Alcatel-Lucent provides support for IPsec in a tunnel mode with encryption,
intended for secure site-to-site communications over an untrusted network.
Currently IPsec can be configured through a crypto map and applied to a
interface.In addition, IPsec as a tunnel interface is required so that,
•
Pre, post encryption or decryption policies for QoS, Filters, and ACL can be
applied.
•
Traffic classifier will be routed based rather than policy based, which means that
routing can control what traffic needs to be secure.
•
Tunnel fail over can be handled by having traffic routed through another tunnel
interface.
•
Allows to run dynamic routing protocols over the tunnel.
B
EFORE
Y
OU
C
ONFIGURE
IP
SEC
T
UNNEL
I
NTERFACE
Here are a few guidelines that you need to pay attention to when configuring the
OA-700 for the IPsec Tunnel interface.
1.
Routing setup must be in ordinance.
2.
The interface must be a configurable interface, i.e., associated with an IP address.
3.
Tunnel endpoints (source and destination) should be specified. The source
address could be a configured IP address or another interface address (thus
deriving its IP address). The destination address is the address of the peer with
which IKE negotiation will take place.
4.
Parameters required in tunnel negotiation should be configured. These
parameters are IPsec transform set, IKE policy, SA lifetime, PFS, and IKE Identity.
Summary of Contents for OmniAccess 700
Page 38: ...Left running head Chapter name automatic 12 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Page 176: ...Left running head Chapter name automatic 150 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Page 260: ...Left running head Chapter name automatic 234 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Page 434: ...Left running head Chapter name automatic 408 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Page 464: ...Left running head Chapter name automatic 438 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Page 638: ...Left running head Chapter name automatic 612 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Page 940: ...Left running head Chapter name automatic 914 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Page 1002: ...Left running head Chapter name automatic 976 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Page 1120: ...Left running head Chapter name automatic 2 Beta Beta CLI Configuration Guide Alcatel Lucent ...