Cisco WS-SVC-IPSEC-1= - IPSec VPN Services Module Informações Técnicas

Consulte online ou descarregue Informações Técnicas para Redes Cisco WS-SVC-IPSEC-1= - IPSec VPN Services Module. Cisco WS-SVC-IPSEC-1= - IPSec VPN Services Module Technical information [en] [fr] [nl] Manual do Utilizador

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 98
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 0
Corporate Headquarters:
Copyright © 2002–2003 Cisco Systems, Inc. All rights reserved.
Cisco Systems, Inc., 170 West Tasman Drive, San Jose, CA 95134-1706 USA
IPSec VPN Acceleration Services Module
Installation and Configuration Note
Product Number: WS-SVC-IPSEC-1
This publication describes how to install and configure the IPSec Virtual Private Network (VPN)
Acceleration Services Module in the Catalyst 6500 series switches and Cisco 7600 Series Internet
Routers.
Note Throughout this publication, the IPSec VPN Acceleration Services Module is referred to as the
VPN module.
Note Throughout this publication, the term crypto is used to refer to cryptographic.
Note For information on the latest caveats and updates for the VPN module, refer to the following
publications:
Cisco IOS Release 12.2(9)YO4 or later release notes at this URL:
http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/relnotes/ol_2864.htm
Cisco IOS Release 12.2(14)SY or later release notes at this URL:
http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/relnotes/ol_3975.htm
Vista de página 0
1 2 3 4 5 6 ... 97 98

Resumo do Conteúdo

Página 1 - Corporate Headquarters:

Corporate Headquarters:Copyright © 2002–2003 Cisco Systems, Inc. All rights reserved.Cisco Systems, Inc., 170 West Tasman Drive, San Jose, CA 95134-17

Página 2 - Contents

10IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Installing and Removing the VPN ModuleInstalling and Rem

Página 3

11IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Installing and Removing the VPN ModuleWarningOnly traine

Página 4 - Port VLAN and Interface VLAN

12IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Installing and Removing the VPN ModuleCaution During thi

Página 5 - Supported Features

13IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Installing and Removing the VPN ModuleStep 2 Loosen the

Página 6

14IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Installing and Removing the VPN ModuleWarningBefore you

Página 7 - Software Requirements

17IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Installing and Removing the VPN ModuleVertical slotsa. P

Página 8 - Hardware Requirements

20IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Installing and Removing the VPN ModuleFigure 8 Ejector L

Página 9 - Front Panel Description

21IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleConfiguring a VPN

Página 10 - Safety Overview

22IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleNote Switching to

Página 11 - 78-14459-03 Rev C0

23IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module• WAN interface:–s

Página 12 - Removing a VPN Module

2IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0ContentsContentsThis publication consists of these sectio

Página 13 - Installing a VPN Module

24IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleRouted Port Mode S

Página 14 - Horizontal slots

25IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleVPN Module Configu

Página 15 - Vertical slots

26IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module• Switched Port An

Página 16 - Verifying the Installation

27IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleWhen you enter the

Página 17

28IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleMiscellaneous Guid

Página 18

29IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleHandling Multicast

Página 19 - Configuration Summaries

30IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module• If you insert a

Página 20 - Trunk Port Mode Summary

31IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module• The interface MT

Página 21

32IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleTo remove the inte

Página 22

33IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleConfiguring the VP

Página 23

3IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Understanding How the VPN Module WorksWhen you configure

Página 24 - Miscellaneous Guidelines

34IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module• As with single V

Página 25 - Handling Multicast Traffic

35IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module set transform-set

Página 26 - Configuring MTU Settings

36IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module crypto connect vl

Página 27 - Configuring Trunk Ports

37IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleFor complete confi

Página 28

38IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleActive# show runBu

Página 29

39IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module standby track Gig

Página 30

40IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleThe following is a

Página 31

41IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module standby delay min

Página 32

42IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleUsing IPSec NAT Tr

Página 33

43IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleThe following is a

Página 34

4IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Understanding How the VPN Module WorksVPN Module Outside

Página 35

44IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Moduleredundancymain-cpu

Página 36

45IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleUsing Dead-Peer-De

Página 37

46IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleCrypto Connection

Página 38 - Using Easy-VPN Client

47IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module crypto connect vl

Página 39

48IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module!interface Gigabit

Página 40

49IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module crypto connect vl

Página 41 - Using WAN Interfaces

50IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleFollow these guide

Página 42

51IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleUsing QoSNote This

Página 43 - • VLAN 101—ATM6/0/0.101

52IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleConfiguring a VPN

Página 44 - • VLAN 16—pos6/1/0.16

53IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleStep 5 From privil

Página 45 - Using GRE Tunneling

5IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Supported FeaturesPort VLAN 501 and port VLAN 502 are the

Página 46

54IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleConfiguring a VPN

Página 47 - Port Configuration Procedures

55IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleStep 6 From interf

Página 48

56IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleFigure 12 Trunk Po

Página 49

57IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleStep 6 From interf

Página 50

58IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration ExamplesDisplaying the VPN Running StateUs

Página 51

59IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration ExamplesCatalyst Switch 1 (Access Port)The

Página 52

60IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples no ip address flowcontrol receive

Página 53

61IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration ExamplesFigure 13 Access Port Configuration

Página 54 - Configuration Examples

62IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration ExamplesCatalyst Switch 2 (Access Port)The

Página 55

63IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examplesinterface GigabitEthernet5/1 switc

Página 56

6IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Supported Features• Capacity–8000 tunnels (no IKE keepali

Página 57

64IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration ExamplesCatalyst Switch 1 (Routed Port)The

Página 58

65IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examplesinterface GigabitEthernet5/2 switc

Página 59 - Routed Ports

66IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration ExamplesFigure 14 Routed Port Configuration

Página 60

67IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examplesredundancy main-cpu auto-sync sta

Página 61

68IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examplesinterface Vlan1 no ip address shut

Página 62

69IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples!crypto isakmp policy 1 encr 3des

Página 63

70IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples!!ip access-list extended AEO-101

Página 64 - Trunk Ports

71IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration ExamplesCatalyst Switch 2 (Trunk Port)The

Página 65

72IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examplesinterface GigabitEthernet5/1 switc

Página 66

73IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration ExamplesATM PortsNote This section applies

Página 67

7IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Hardware and Software Requirements–PA-MC-2T1: 2-port mult

Página 68

74IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples auto-sync standard!controller T3

Página 69 - ATM Ports

75IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples crypto connect vlan 6!interface S

Página 70

76IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples cdp enable!interface GigabitEther

Página 71

77IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration ExamplesCatalyst Switch 2 (ATM Port)The Ca

Página 72

78IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples multilink-group 1...!interface Mu

Página 73 - Catalyst Switch 2 (ATM Port)

79IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples ip address 10.10.20.254 255.255.2

Página 74

80IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration ExamplesCatalyst Switch 1 (Frame Relay Por

Página 75 - Frame Relay Ports

81IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examplesvlan 1 tb-vlan1 1002 tb-vlan2 1003

Página 76

82IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examplesinterface FastEthernet3/2 no ip ad

Página 77

83IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples clock source internal frame-relay

Página 78

8IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Hardware and Software RequirementsHardware RequirementsTh

Página 79

84IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples!crypto isakmp policy 1 encr 3des

Página 80

85IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples no ip address no fair-queue!inter

Página 81

86IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examplesno ip http serverno ip http secure

Página 82 - GRE Tunneling

87IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples flowcontrol send off switchport s

Página 83 - Catalyst Switch 2

88IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples switchport mode trunk cdp enable!

Página 84

89IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples!boot system flash sup-bootflash:!

Página 85

90IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples no ip address snmp trap link-stat

Página 86

91IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples!!no ip domain-lookup!!no mls ip m

Página 87

92IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples cdp enable!interface Vlan1 no ip

Página 88

93IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examplescrypto isakmp policy 1 encr 3des a

Página 89

9IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Front Panel DescriptionNote The FlexWAN module and the Op

Página 90 - Switch 1 Configuration

94IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples!line con 0line vty 0 4 login tran

Página 91

95IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples!!! Enables qos globallymls qos!cr

Página 92 - Switch 2 Configuration

96IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples switchport trunk allowed vlan 1,1

Página 93

97IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examplescrypto ipsec transform-set 3des_sh

Página 94 - Obtaining Documentation

98IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Regulatory Standards Complianceno ip http serverno ip ht

Página 95 - Documentation Feedback

99IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Obtaining DocumentationDocumentation CD-ROMCisco documen

Página 96 - Technical Assistance Center

100IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Obtaining Technical AssistanceObtaining Technical Assis

Página 97 - Cisco TAC Escalation Center

101IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Obtaining Additional Publications and InformationAll cu

Página 98

102IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Obtaining Additional Publications and Information• Inte

Comentários a estes Manuais

Sem comentários