Technical information
67
IPSec VPN Acceleration Services Module Installation and Configuration Note
78-14459-03 Rev C0
Configuration Examples
redundancy
main-cpu
auto-sync standard
diagnostic level complete
ip subnet-zero
!
!
no ip domain-lookup
!
ip ssh time-out 120
ip ssh authentication-retries 3
!
!
crypto isakmp policy 1
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp key Jolly-Good-Fellow address 192.168.100.253
!
!
crypto ipsec transform-set TS-101 esp-3des esp-sha-hmac
!
crypto map MAP-101 10 ipsec-isakmp
set peer 192.168.100.253
set security-association lifetime kilobytes 10000
set security-association lifetime seconds 86000
set transform-set TS-101
match address AEO-101
!
!
!
!
interface GigabitEthernet1/1
ip address 10.83.3.254 255.255.255.0
!
interface GigabitEthernet1/2
no ip address
crypto connect vlan 513
!
interface GigabitEthernet5/1
switchport
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 1,513,1002-1005
switchport mode trunk
no ip address
flowcontrol receive on
!
interface GigabitEthernet5/2
switchport
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 1,1002-1005
switchport mode trunk
no ip address
flowcontrol receive on
!