IPsec Tunnel Interface Configuration
Except on the first page, right running head:
Heading1 or Heading1NewPage text (automatic)
873
Alcatel-Lucent
Beta Beta
OmniAccess 5740 Unified Services Gateway CLI Configuration Guide
IPSEC TUNNEL INTERFACE CONFIGURATION
Refer to the following sections for configuring IPsec tunnel interface:
• “IPsec Tunnel Interface Configuration Commands”
• “IPsec VPN Configuration Flow”
• “IPsec Configuration Commands”
• “IPsec VPN Show Commands”
IPSEC TUNNEL INTERFACE CONFIGURATION STEPS
The following are the steps to configure IPsec tunnel interface on the OmniAccess
5740 USG:
Step 1: Following IPsec VPN configuration is pre-requisite for IPsec tunnel
configuration. These are mandatory for IPsec tunnel functioning.
The configurations for all these parameters (preshared key/X.509
certificates, IKE policy, Transform Set) are already given in the earlier
sections of the document; hence it is not repeated in this section. Use the
links to see the specific commands.
• Configure preshared key. See “IPsec Configuration with Preshared Key”
Note: While configuring preshared key for IPsec Tunnel interface, the peer address should
be the destination IP address configured on the tunnel interface.
OR
Configure X.509 certificates. See “IPsec Configuration with X.509
Certificates”
• Configure IKE policy. See “To Configure an IKE Policy”
• Configure a Transform Set. See “To Configure Transform-set in IPsec”
Step 2: Configure IPsec Profile. See “To Configure IPsec Profile”. And, configure
Profile related commands.
• Attach an IKE policy to an IPsec profile. See “To Attach an IKE Policy to an
IPsec Profile”
• Attach a transform set to an IPsec profile. See “To Attach a Transform Set to
an IPsec Profile”