• ip-protocol
• tcp
• udp
• icmp
• dscp
• fragment
• Access control list –
on page 498
•
- crypto isakmp invalid-spi-recovery
- crypto ipsec nat-transparency udp-encapsulation
- crypto isakmp nat keepalive
•
assigning a crypto-list to an interface
on page 500
- crypto ipsec df-bit
- crypto ipsec minimal-pmtu
-
ip crypto-group
Site-to-site IPSec VPN
This section describes the concepts and procedures for VPN configuration.
To configure a site-to-site IPSec VPN, two devices (the Branch Gateway and a peer Gateway)
must be configured symmetrically.
In some cases, you may wish to configure global VPN parameters (see
on page 499).
Note:
In the following sections, all IPSec VPN parameters that you must configure are indicated
as mandatory parameters. Non-mandatory VPN parameters have default values that are
used unless otherwise set. Thus for example, although it is mandatory to define at least one
ISAKMP policy, it is not mandatory to set the values for that ISAKMP policy since the Branch
Gateway contains default ISAKMP policy settings.
Related topics:
on page 486
on page 488
Configuring ISAKMP peer information
IPSec VPN
Administering Avaya G430 Branch Gateway
October 2013 485
Summary of Contents for G430
Page 1: ...Administering Avaya G430 Branch Gateway Release 6 3 03 603228 Issue 5 October 2013 ...
Page 12: ...12 Administering Avaya G430 Branch Gateway October 2013 ...
Page 246: ...VoIP QoS 246 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...
Page 556: ...IPSec VPN 556 Administering Avaya G430 Branch Gateway October 2013 Comments infodev avaya com ...