X hits on this document

PDF document

Cisco AVVID Network Infrastructure IP Multicast Design - page 73 / 98

226 views

0 shares

0 downloads

0 comments

73 / 98

Chapter 6

IP Multicast in a Site-to-Site VPN

VPN Deployment Model

Branch

Following is the crypto map configuration for VPN-Branch-1.

interface Serial0/0 description to ISP for VPN ip address 131.108.101.1 255.255.255.252 ! crypto map static-map local-address Serial0/0 ! crypto map static-map 1 ipsec-isakmp set peer 131.108.1.1 set transform-set strong match address toHE-1 crypto map static-map 2 ipsec-isakmp set peer 131.108.1.5 set transform-set strong match address toHE-2

Following is the crypto map configuration for VPN-Branch-2.

interface Serial0 description to ISP for VPN ip address 131.108.102.1 255.255.255.252 ! crypto map static-map local-address Serial0 ! crypto map static-map 1 ipsec-isakmp set peer 131.108.1.5 set transform-set strong match address toHE-2 crypto map static-map 2 ipsec-isakmp set peer 131.108.1.1 set transform-set strong match address toHE-1

Tip

A more complete description can be found at: http://www.cisco.com/univercd/cc/td/doc/product/ software/ios122/122cgcr/fsecur_r/fipsencr/srfipsec.htm#xtocid105785

Applying Crypto Maps

The crypto maps must be applied to both the physical interface and the logical interfaces, such as the GRE tunnel interfaces.In the examples below, the delay statements applied to the tunnel interfaces have been weighted so that traffic will prefer the tunnel that has been designated the primary tunnel.

Cisco AVVID Network Infrastructure IP Multicast Design

956651

6-9

Document info
Document views226
Page views226
Page last viewedWed Dec 07 21:06:35 UTC 2016
Pages98
Paragraphs2650
Words25637

Comments