VPN Configuration
Configure IPsec crypto maps and DTP settings for the branch switches in a branch config group by navigating
to Configuration>Branch>Smart Config and selecting the VPN tab. The settings on the VPN tab are
described in the table below.
Parameter Description
Description
IPSec maps
Name
Name of the IPsec map.
Disable IPsec map
Click this checkbox to temporarily disable a configured IPsec map without
deleting it from the branch config group.
Priority
Priority level for the IPsec map, from 1-9998. An IPsec map with a smaller pri-
ority number will take precedence over a map with a greater priority num-
ber.
Source Network Type Select one of the supported source network identifier types:
n IP Address: Identify the source network (the local network connected to
the branch switch) using an IP address.
n VLAN:Use a VLANID as the source network. When the configuration is
pushed to the branch, the IP address range assigned for that VLAN in
that branch is used during IKE negotiation.
n Any: Use any as the source network.
Source Network
If you selected the IPAddress source network type, enter the IP address
the source network in the Source Network field
Source Network VLAN If you selected VLAN as the source network type, click the VLAN drop-down
list and select the VLANID of the source network VLAN.
Source Subnet Mask
Subnet mask for the source network (the local network connected to the
branch switch).
Destination Network Select one of the supported destination network identifier types:
n IP Address: Identify the destination network (the remote network to
which the local branch network communicates).
n Any: Use any as the destination network.
Destination Subnet Mask
Subnet mask for the source network (the remote network to which the local
branch network communicates).
Peer Gateway Type Select one of the supported peer gateway types:
n IP Address: Select this option to identify the remote end point of the VPN
tunnel using an IP address.
n FQDN :This option allows you to use same FQDN across different
branches. The FQDN resolves to different IP addresses for each branch,
based on its local DNS setting.
Table 68: Branch Config Group VPN Settings
AOS-W 6.5.3.x | User Guide BranchSwitch Config for Cloud Services Switches | 247