desintation-ip any
source-ip host <Branch Subnet1> <Branch Subnet1 Mask>
composite-operation Permit
exit
ip-rule 50
destination-ip any
source-ip host <Branch Subnet2> <Branch Subnet2 Mask>
composite-operation Permit
exit
ip-rule default
composite-operation deny
exit
exit
interface vlan 1.1
ip-address <Branch Subnet1> <Branch Subnet1 Mask>
pmi
icc-vlan
exit
interface vlan 1.2
ip-address <Branch Subnet2> <Branch Subnet2 Mask>
exit
interface fastethernet 10/3
encapsulation PPPoE
traffic-shape rate 256000
ip Address <Branch Office Public Internet Static IP Address>
<Branch Office Public Internet network mask>
ip crypto-group 901
ip access-group 301 in
ip access-group 302 out
exit
ip default-gateway FastEthernet 10/3 high
Note:
The highlighted commands are the CLI commands that add the mesh capabilities to the
simple hub and spokes configuration.
Branch Office 2 configuration
crypto isakmp policy 1
encryption aes
hash sha
group 2
exit
crypto isakmp peer address <Main Office Public Internet Static IP
Address>
pre-shared-key <secret key>
isakmp-policy 1
exit
crypto isakmp peer address <First Branch Office Public Internet Static IP
Address>
pre-shared-key <secret key 2>
isakmp-policy 1
exit
crypto ipsec transform-set ts1 esp-3des esp-sha-hmac
set pfs 2
exit
crypto map 1
set peer <Main Office Public Internet Static IP Address>
set transform-set ts1
exit
crypto map 2
IPSec VPN
520 Administering Avaya G430 Branch Gateway October 2013
Comments? infodev@avaya.com