EasyManuals Logo
Home>Cisco>Network Router>2911

Cisco 2911 Configuration Guide

Cisco 2911
408 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #148 background imageLoading...
Page #148 background image
140
Cisco 3900 Series, Cisco 2900 Series, and Cisco 1900 Series Integrated Services Routers Generation 2 Software Configuration Guide
Chapter Configuring Security Features
Configuring VPN
Configure IPSec Transforms and Protocols
A transform set represents a certain combination of security protocols and algorithms. During IKE
negotiation, the peers agree to use a particular transform set for protecting data flow.
During IKE negotiations, the peers search multiple transform sets for a transform that is the same at both
peers. When a transform set is found that contains such a transform, it is selected and applied to the
protected traffic as a part of both peers’ configurations.
To specify the IPSec transform set and protocols, follow these steps, beginning in global configuration
mode.
SUMMARY STEPS
1. crypto ipsec profile profile-name
2. crypto ipsec transform-set transform-set-name
3. crypto ipsec security-association lifetime {seconds seconds | kilobytes kilobytes}
DETAILED STEPS
Command or Action Purpose
Step 1
crypto ipsec profile profile-name
Example:
Router(config)# crypto ipsec profile pro1
Router(config)#
Configures an IPSec profile to apply protection on
the tunnel for encryption.
Step 2
crypto ipsec transform-set transform-set-name
transform1 [transform2] [transform3]
[transform4]
Example:
Router(config)# crypto ipsec transform-set
vpn1 esp-3des esp-sha-hmac
Router(config)#
Defines a transform set—an acceptable
combination of IPSec security protocols and
algorithms.
See Cisco IOS Security Command Reference for
detail about the valid transforms and
combinations.
Step 3
crypto ipsec security-association lifetime
{seconds seconds | kilobytes kilobytes}
Example:
Router(config)# crypto ipsec
security-association lifetime seconds 86400
Router(config)#
Specifies global lifetime values used when IPSec
security associations are negotiated.
See Cisco IOS Security Command Reference for
details.

Table of Contents

Other manuals for Cisco 2911

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 2911 and is the answer not in the manual?

Cisco 2911 Specifications

General IconGeneral
Ethernet LANYes
Cabling technology10/100/1000Base-T(X)
Networking standardsIEEE 802.1Q, IEEE 802.1ag, IEEE 802.3, IEEE 802.3ab, IEEE 802.3af, IEEE 802.3ah, IEEE 802.3u
Ethernet LAN data rates10, 100, 1000 Mbit/s
Ethernet interface typeGigabit Ethernet
DHCP client-
Routing protocolsBGP, EIGRP, OSPF
Supported protocolsIPv4, IPv6, IS-IS, IGMPv3, PIM SM, SSM, DVMRP, IPSec, GRE, BVD, MPLS, L2TPv3, PPP, MLPPP, MLFR, HDLC, RS-232, RS-449, X.21, V.35, EIA-530, PPPoE, ATM
USB version2.0
RS-232 ports1
Expansion slots4 x EHWIC 2 x DSP 1 x ISM
USB ports quantity2
Ethernet LAN (RJ-45) ports3
Firewall securityCisco IOS
Input current2.2 A
AC input voltage100 - 240 V
Power source typeAC
AC input frequency47 - 63 Hz
Power consumption (typical)50 W
Product colorBlack
Rack capacity2U
Operating altitude0 - 4000 m
Non-operating altitude0 - 4570 m
Storage temperature (T-T)-40 - 80 °C
Operating temperature (T-T)0 - 40 °C
Storage relative humidity (H-H)5 - 95 %
Operating relative humidity (H-H)5 - 85 %
SafetyUL 60950-1, CAN/CSA C22.2 No. 60950-1, EN 60950-1, AS/NZS 60950-1, IEC 60950-1
Electromagnetic compatibility47 CFR, ICES-003, EN55022, CISPR22, AS/NZS 3548, VCCI V-3, EN 300-386, EN 61000, EN 55024, CISPR 24EN50082-1
Weight and Dimensions IconWeight and Dimensions
Depth304.8 mm
Width438.2 mm
Height88.9 mm
Weight8200 g

Related product manuals