![]() ![]() ![]() Konfiguracia IKE a IPSEC je na oboch zariadeniach zhodna, jedine co sa meni je IKE-GW kde treba nastavit spravny external-interface a remote ip adresu. Set security ipsec proposal IPSEC-prop encryption-algorithm aes-128-cbc Set security ipsec proposal IPSEC-prop authentication-algorithm hmac-sha1-96 Set security ipsec proposal IPSEC-prop protocol esp Teraz prejdeme k druhej faze IPSEC, najprv vytovrime IPSEC proposal IPSEC-prop opat mozno pouzit aj defaultny standard Set security ike gateway IKE-gw external-interface fe-0/0/0 Set security ike gateway IKE-gw address 80.94.50.5 Set security ike gateway IKE-gw ike-policy IKE-pol Set security ike policy IKE-pol pre-shared-key ascii-text my-pre-shared-keyĪ ako posledne nastavime IKE gateway, kde nastavime nase IKE policy, interface cez ktory sa pripajame k remote srx a ip adresu remote srx Set security ike policy IKE-pol proposals IKE-prop Set security ike policy IKE-pol mode main Set security ike proposal IKE-prop lifetime-seconds 3600set security ike gateway IKE-gw ike-policy IKE-pol Set security ike proposal IKE-prop encryption-algorithm aes-128-cbc Set security ike proposal IKE-prop authentication-algorithm sha1 Set security ike proposal IKE-prop dh-group group2 Set security ike proposal IKE-prop authentication-method pre-shared-keys Vytvorime IKE proposal IKE-prop, je mozne pouzit aj default proposal napr. ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |