D-Link DI-3660 [361/506] Crypto map map name seq num

D-Link DI-3660 [361/506] Crypto map map name seq num
Command Line Interface Reference Manual
361
  (00)peer       Allowed Encryption/Decryption peer. 
  (01)security-association    Security association parameters 
  (02)transform-set     Specify list of transform sets  
  Please Input the code of command to be excute(0-2):  
  Key Word: 
  Q(quit) 
  (00)inbound       Inbound manual security association 
  (01)outbound       Outbound manual security association 
  Please Input the code of command to be excute(0-1):  
  Key Word: 
  Q(quit) 
  (00)ah         AH key 
  (01)esp        ESP key 
  Please Input the code of command to be excute(0-1):  
  Key Word: 
  Q(quit) 
  (00)<256-4294967295>     SPI for security association 
  Please Input the code of command to be excute(0-0):  
  Please input a digital number:20000 Input SPI Value 
  Key Word: 
  Q(quit) 
  (00)WORD       security association key value (hex w/o leading 0x) 
  Please Input the code of command to be excute(0-0): 0 
  Please input a string:654321 input security association key value  
  Will you excute it? (Y/N): 
  Key Word: 
  Q(quit) 
  …… 
  (05)english       help message in English 
  (06)exit       exit / quit 
  …… 
  Please Input the code of command to be excute(0-19):  
  Will you excute it? (Y/N): 
Repeat these steps to create additional crypto map entries as required.
Creat Crypto Map Entries that Used IKE
To create crypto map entries that will use IKE to establish the security associations, use the following commands starting
in global configuration mode:
Step
Command Purpose
1
crypto map map-name seq-num
ipsec-isakmp
Specifies the crypto map entry to create (or modify). Perform
this command into the crypto map configuration mode.
2
Match address access-list-name
Configure an IPSec access list. This access list determines
which traffic should be protected by IPSec a
nd which traffic
should not be protected by IPSec security in the context of
this crypto map entry.
3
set peer ip-address
Specifies the address of IPSec peer. This is the address to
which IPSec protected traffic should be forwarded.
4
set transform-set transform-set-name1
Configure transform sets. No more than six crypto map

Содержание

Скачать