CHAPTER 5. IPSEC
262
© SAMSUNG Electronics Co., Ltd.
Proposal of priority 1
Protocol: esp
Mode: tunnel
Encryption Algorithm: aes128(key length=128 bits)
Hash Algorithm: sha1
Lifetime in seconds: 3600
Lifetime in Kilobytes: 4608000
11.
Configure firewall policies to allow IKE negotiation through untrusted
interface.
Router/configure# firewall internet
Router/configure/firewall internet# policy 1000 in service
ike self
Router/configure/firewall internet/policy 1000 in# exit
Router/configure/firewall internet# exit
12.
Configure firewall policies to allow desired services through untrusted
interface to manage the router.
Router/configure# firewall internet
Router/configure/firewall internet# policy 1001 in service
snmp self
Router/configure/firewall internet/policy 1001 in# exit
Router/configure/firewall internet# policy 1002 in service
telnet self
Router/configure/firewall internet/policy 1002 in# exit
Router/configure/firewall internet# policy 1003 in protocol
icmp self
13.
Display firewall policies in the internet map.
Router# show firewall policy internet
Advanced: S-Self Traffic, F-Ftp-Filter, H-Http-Filter,
R-Rpc-Filter, N-Nat-Ip/Nat-Pool, L-Logging,
E-Policy Enabled, M-Smtp-Filter
Pri Dir Source Addr Destination Addr Sport Dport Proto
Action Advanced
--- --- ----------- ---------------- ----------------- -----
- --------
Summary of Contents for Ubigate iBG2016
Page 1: ......
Page 16: ...INTRODUCTION XIV SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 34: ......
Page 62: ...CHAPTER 4 System Logging 28 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 70: ......
Page 108: ......
Page 140: ...CHAPTER 4 RIP 104 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 156: ...CHAPTER 6 BGP 120 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 180: ...CHAPTER 8 VRRP 144 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 264: ...CHAPTER 10 QoS 228 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 272: ......
Page 298: ...CHAPTER 3 Firewall NAT 248 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 356: ...CHAPTER 5 IPSEC 306 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 358: ......
Page 744: ...EQBD 000071 Ed 00 ...