CHAPTER 5. IPSEC
296
© SAMSUNG Electronics Co., Ltd.
outbound ESP sas
Spi: 0xcfea8435
Transform: aes256(key length=256 bits), sha1
In use settings = {tunnel}
Bytes Processed 240
Hard lifetime in seconds 28780, Hard lifetime in
kilobytes is unlimited
Soft lifetime in seconds 28690, Soft lifetime in
kilobytes is unlimited
Configuring IPSec Remote Access Example
The following example demonstrates how to configure a router to be an IPSec
VPN server using mode-configuration method. The client could be any
standard mode configuration enabled IPSec VPN client.
In this example, the client needs to access the corporate private network
10.0.1.0/24 through the VPN tunnel. The server has a pool of ip addresses
from 20.1.1.100 through 20.1.1.150 to be allocated for mode configuration
enabled VPN clients. The assigned IP address will be used by the VPN client
as the source address in the inner IP header. The outer IP header will carry the
dynamic IP address assigned by the Internet Service Provider as the source
address.
The security requirements are as follows:
y
Phase 1: 3DES with SHA1, Mode Configuration
y
Phase 2: IPSec ESP tunnel with AES256 and HMAC-SHA1
Corporate Headquarters
10.0.1.0/24
Router #1
VPN Server
172.16.0.1
Mode Config IP
Pool: 10.0.1.100.10.02.150
IPSec Tunnel
VPN Client 1
Local Outer Address: Dynamic
Local Inner Address: 10.0.1.100/32
Local ID: david@abc-corp.com
VPN Client 1
Local Outer Address: Dynamic
Local Inner Address: 10.0.1.101/32
Local ID: milk@abc-corp.com
IPSec Tunnel
Summary of Contents for Ubigate iBG2016
Page 1: ......
Page 16: ...INTRODUCTION XIV SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 34: ......
Page 62: ...CHAPTER 4 System Logging 28 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 70: ......
Page 108: ......
Page 140: ...CHAPTER 4 RIP 104 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 156: ...CHAPTER 6 BGP 120 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 180: ...CHAPTER 8 VRRP 144 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 264: ...CHAPTER 10 QoS 228 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 272: ......
Page 298: ...CHAPTER 3 Firewall NAT 248 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 356: ...CHAPTER 5 IPSEC 306 SAMSUNG Electronics Co Ltd This page is intentionally left blank ...
Page 358: ......
Page 744: ...EQBD 000071 Ed 00 ...