This section provides information to configure IPSec using the command line interface.
Topics in this section include:
The following list provides a high-level outline for setting up IPSec on the 7705 SAR.
This section provides a brief overview of the following common configuration tasks that must be performed to configure IPSec:
The following output displays an IPSec group configuration in the ISA context. The 7705 SAR supports only one tunnel-group. The tunnel-group-id is always 1.
An IPSec tunnel requires the following three interfaces:
The physical interface is the one that must reside on an encryption-capable adapter card.
The following example displays an interface (“internet”) configured using a network port (1/1/1) and an IES interface (“public”) configuration using SAP 1/1/8.
Under the IPSec context, configure the IKE policy and IPSec transform parameters.
The following example displays the IPSec parameter configuration output.
IPSec is configured under IES and VPRN services.
Under VPRN service, configure IPSec security policies, and create tunnel interfaces, private tunnel SAPs, and IPSec tunnels along with setting the IPSec tunnel parameters. Use the tunnel keyword when creating an interface for a private tunnel SAP.
Under IES service, create an interface and public tunnel SAP. The tunnel keyword is not used when creating an interface for a public tunnel SAP.
Private and public tunnels function in pairs, where a pair is defined by the tag in the sap-id; for example, SAP tunnel-1.private:22 and SAP tunnel-1.public:22 are a pair.
The local gateway address and delivery service configured under the VPRN ipsec-tunnel>local-gateway-address command correspond to the IES interface address and service ID where the public tunnel interface is defined. In the example below, the local-gateway-address is 10.10.10.11 and the delivery-service is 10.
The following example displays the configuration output when configuring IPSec for VPRN services and for IES.
This section provides a brief overview of the following service management tasks:
An IPSec IKE policy or transform cannot be deleted if it is being used by an IPSec tunnel. To delete an IKE policy or IPSec transform:
A public IPSec tunnel interface and SAP are created under IES. To delete a public IPSec tunnel interface and SAP:
A private IPSec tunnel interface and SAP are created under a VPRN service. To delete a private IPSec tunnel interface and SAP:
Security policies are created under the VPRN service. To delete an IPSec security policy:
IPSec tunnels are created under the VPRN service. To delete an IPSec tunnel: