IP Security - Virtual Private Network
Left running head:
Chapter name (automatic)
888
Beta Beta
OmniAccess 5740 Unified Services Gateway CLI Configuration Guide
Alcatel-Lucent
DMVPN CONFIGURATION
Refer to the following sections for configuring IPsec:
• “IPsec VPN Configuration Steps”
• “IPsec VPN Configuration Flow”
• “IPsec Configuration Commands”
• “IPsec VPN Show Commands”
DMVPN CONFIGURATION STEPS
The following are the steps to configure DMVPN on OmniAccess 5740 USG:
Step 1: Configure a NHRP (Next Hop Resolution Protocol) object. See “To
Configure a NHRP Object”
Step 2: Configure parameters under a NHRP object.
• Configure IP address of the NHS in a NHRP object. See “To Configure
Next Hop Server (NHS) IP Address”
• Configure static map entry for NHS. See “To Configure Static Map Entry
for NHS”
• Configure NHS network identifier. See “To Configure NHRP Network
Identifier”
• Configure holdtime for NHRP cache. See “To Configure Holdtime for
NHRP Cache” (Optional)
• Configure registration timeout. See “To Configure Registration Timeout”
(Optional)
• Configure authentication string. See “To Configure Authentication String”
(Optional)
IPsec VPN and IPsec Profile Configuration
Step 1: Configure match-list and match-list rules. For more information on this,
refer to the “Common Classifiers” chapter in this guide.
Step 2: Following IPsec VPN and IPsec Profile configuration is pre-requisite
for DMVPN configuration. These are mandatory for DMVPN functioning.