To create an IPSec tunnel:
- host1(config)#virtual-router vrA
- host1:vrA(config)#
- host1:vrA(config)#interface tunnel ipsec:Aottawa2boston
transport-virtual-router default
- host1:vrA(config-if)#
- host1:vrA(config-if)#ip address 10.3.0.0 255.255.0.0
- host1:vrA(config-if)#tunnel transform-set
customerAprotection
- host1:vrA(config-if)#tunnel local-identity
subnet 10.1.0.0 255.255.0.0
- host1:vrA(config-if)#tunnel peer-identity
subnet 10.3.0.0 255.255.0.0
- host1:vrA(config-if)#tunnel source 5.1.0.1
- host1:vrA(config-if)#tunnel destination identity
branch245.customer77.isp.net
- host1:vrA(config-if)#exit
![]() |
Note: FQDNs are used when tunnel destination endpoints do not have a fixed address, as in cable and DSL environments. |
- host1:vrA(config-if)#tunnel session-key-inbound
esp-des-hmac-md5 a7bd567917bd5679 bd5678a7bd567917bd567917bd567678
- host1:vrA(config-if)#tunnel session-key-outbound
esp-3des-hmac-md5 421 567917bd567917bd567917bd545a17bd567917bd56784a7b
fda183bef567917bd567917bd567917b
- host1:vrA(config-if)#tunnel pfs group 5
- host1:vrA(config-if)#tunnel signaling isakmp
- host1(config-if)#tunnel lifetime seconds 48000
kilobytes 249000
- host1(config-if)#tunnel mtu 2240
interface tunnel
- host1(config)#interface tunnel ipsec:jak transport-virtual-router
tvr041
- host1(config-if)#
tunnel destination
- host1(config-if)#tunnel destination 10.10.11.12
- host1(config-if)#tunnel destination identity
branch245.customer77.isp.net
- host1(config-if)#tunnel destination identity user4919@branch245.customer77.isp.net
tunnel lifetime
- host1(config-if)#tunnel lifetime seconds 48000
kilobytes 249000
tunnel local-identity
- host1(config-if)#tunnel local-identity range
10.10.1.1 10.10.2.1
- host1(config-if)#tunnel local-identity subnet
10.10.1.1 255.255.255.0
tunnel mtu
- host1(config-if)#tunnel mtu 2240
tunnel peer-identity
- host1(config-if)#tunnel peer-identity range
10.10.1.1 10.10.2.2
- host1(config-if)#tunnel peer-identity subnet
130.10.1.1 255.255.255.0
tunnel pfs group
- host1(config-if)#tunnel pfs group 5
tunnel session-key-inbound
- host1(config-if)#tunnel session-key-inbound
esp-des-hmac-md5 a7bd567917bd5679 bd5678a7bd567917bd567917bd567678
tunnel session-key-outbound
- host1(config-if)#tunnel session-key-outbound
esp-3des-hmac-md5 421 567917bd567917bd567917bd545a17bd567917bd56784a7b
fda183bef567917bd567917bd567917b
tunnel signaling
- host1(config-if)#tunnel signaling manual
tunnel source
- host1(config-if)#tunnel source 10.10.2.8
tunnel transform-set
- host1(config-if)#tunnel transform-set espSet