DMVPN Configuration
Except on the first page, right running head:
Heading1 or Heading1NewPage text (automatic)
889
Alcatel-Lucent
Beta Beta
OmniAccess 5740 Unified Services Gateway CLI Configuration Guide
The configurations for all these parameters (pre-shared key/X.509
certificates, IKE policy, Transform Set) are already given in the earlier
sections of the document; hence it is not repeated in this section. Use the
links to see the specific commands.
• Configure pre-shared key. See “IPsec Configuration with Preshared Key”
Note: While configuring Pre-shared key for DMVPN, the peer address should always be
0.0.0.0.
OR
Configure X.509 certificates. See “IPsec Configuration with X.509
Certificates”
• Configure IKE policy. See “To Configure an IKE Policy”
• Configure a Transform Set. See “To Configure Transform-set in IPsec”
Step 3: Configure IPsec Profile. See “To Configure IPsec Profile”. And, configure
Profile related commands.
• Attach an IKE policy to an IPsec profile. See “To Attach an IKE Policy to an
IPsec Profile”
• Attach a transform set to an IPsec profile. See “To Attach a Transform Set to
an IPsec Profile”
• Attach PFS group to an IPsec profile. See “To Attach PFS Group to an IPsec
Profile”
• Configure lifetime for an IPsec profile. See “To Configure Lifetime for an IPsec
Profile”
• Attach an IKE identity to an IPsec profile if the authentication type is ‘rsa-sig’.
See “To Attach an IKE Identity to an IPsec Profile”
Step 4: Configure a Tunnel interface. See “To Configure a Tunnel Interface”
• Administratively bring up the tunnel interface. See “To Administratively Bring
Up/Shutdown the Tunnel Interface”
• Configure IP address for the tunnel interface. See “To Configure IP Address
on a Tunnel Interface”