Cisco WS-SVC-IPSEC-1= - IPSec VPN Services Module Technical Information

Browse online or download Technical Information for Networking Cisco WS-SVC-IPSEC-1= - IPSec VPN Services Module. Cisco WS-SVC-IPSEC-1= - IPSec VPN Services Module Technical information [en] [fr] [nl] User Manual

  • Download
  • Add to my manuals
  • Print
  • Page
    / 98
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 0
Corporate Headquarters:
Copyright © 2002–2003 Cisco Systems, Inc. All rights reserved.
Cisco Systems, Inc., 170 West Tasman Drive, San Jose, CA 95134-1706 USA
IPSec VPN Acceleration Services Module
Installation and Configuration Note
Product Number: WS-SVC-IPSEC-1
This publication describes how to install and configure the IPSec Virtual Private Network (VPN)
Acceleration Services Module in the Catalyst 6500 series switches and Cisco 7600 Series Internet
Routers.
Note Throughout this publication, the IPSec VPN Acceleration Services Module is referred to as the
VPN module.
Note Throughout this publication, the term crypto is used to refer to cryptographic.
Note For information on the latest caveats and updates for the VPN module, refer to the following
publications:
Cisco IOS Release 12.2(9)YO4 or later release notes at this URL:
http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/relnotes/ol_2864.htm
Cisco IOS Release 12.2(14)SY or later release notes at this URL:
http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/relnotes/ol_3975.htm
Page view 0
1 2 3 4 5 6 ... 97 98

Summary of Contents

Page 1 - Corporate Headquarters:

Corporate Headquarters:Copyright © 2002–2003 Cisco Systems, Inc. All rights reserved.Cisco Systems, Inc., 170 West Tasman Drive, San Jose, CA 95134-17

Page 2 - Contents

10IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Installing and Removing the VPN ModuleInstalling and Rem

Page 3

11IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Installing and Removing the VPN ModuleWarningOnly traine

Page 4 - Port VLAN and Interface VLAN

12IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Installing and Removing the VPN ModuleCaution During thi

Page 5 - Supported Features

13IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Installing and Removing the VPN ModuleStep 2 Loosen the

Page 6

14IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Installing and Removing the VPN ModuleWarningBefore you

Page 7 - Software Requirements

17IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Installing and Removing the VPN ModuleVertical slotsa. P

Page 8 - Hardware Requirements

20IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Installing and Removing the VPN ModuleFigure 8 Ejector L

Page 9 - Front Panel Description

21IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleConfiguring a VPN

Page 10 - Safety Overview

22IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleNote Switching to

Page 11 - 78-14459-03 Rev C0

23IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module• WAN interface:–s

Page 12 - Removing a VPN Module

2IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0ContentsContentsThis publication consists of these sectio

Page 13 - Installing a VPN Module

24IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleRouted Port Mode S

Page 14 - Horizontal slots

25IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleVPN Module Configu

Page 15 - Vertical slots

26IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module• Switched Port An

Page 16 - Verifying the Installation

27IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleWhen you enter the

Page 17

28IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleMiscellaneous Guid

Page 18

29IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleHandling Multicast

Page 19 - Configuration Summaries

30IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module• If you insert a

Page 20 - Trunk Port Mode Summary

31IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module• The interface MT

Page 21

32IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleTo remove the inte

Page 22

33IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleConfiguring the VP

Page 23

3IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Understanding How the VPN Module WorksWhen you configure

Page 24 - Miscellaneous Guidelines

34IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module• As with single V

Page 25 - Handling Multicast Traffic

35IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module set transform-set

Page 26 - Configuring MTU Settings

36IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module crypto connect vl

Page 27 - Configuring Trunk Ports

37IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleFor complete confi

Page 28

38IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleActive# show runBu

Page 29

39IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module standby track Gig

Page 30

40IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleThe following is a

Page 31

41IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module standby delay min

Page 32

42IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleUsing IPSec NAT Tr

Page 33

43IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleThe following is a

Page 34

4IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Understanding How the VPN Module WorksVPN Module Outside

Page 35

44IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Moduleredundancymain-cpu

Page 36

45IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleUsing Dead-Peer-De

Page 37

46IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleCrypto Connection

Page 38 - Using Easy-VPN Client

47IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module crypto connect vl

Page 39

48IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module!interface Gigabit

Page 40

49IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN Module crypto connect vl

Page 41 - Using WAN Interfaces

50IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleFollow these guide

Page 42

51IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleUsing QoSNote This

Page 43 - • VLAN 101—ATM6/0/0.101

52IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleConfiguring a VPN

Page 44 - • VLAN 16—pos6/1/0.16

53IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleStep 5 From privil

Page 45 - Using GRE Tunneling

5IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Supported FeaturesPort VLAN 501 and port VLAN 502 are the

Page 46

54IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleConfiguring a VPN

Page 47 - Port Configuration Procedures

55IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleStep 6 From interf

Page 48

56IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleFigure 12 Trunk Po

Page 49

57IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuring a VPN Using the VPN ModuleStep 6 From interf

Page 50

58IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration ExamplesDisplaying the VPN Running StateUs

Page 51

59IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration ExamplesCatalyst Switch 1 (Access Port)The

Page 52

60IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples no ip address flowcontrol receive

Page 53

61IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration ExamplesFigure 13 Access Port Configuration

Page 54 - Configuration Examples

62IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration ExamplesCatalyst Switch 2 (Access Port)The

Page 55

63IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examplesinterface GigabitEthernet5/1 switc

Page 56

6IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Supported Features• Capacity–8000 tunnels (no IKE keepali

Page 57

64IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration ExamplesCatalyst Switch 1 (Routed Port)The

Page 58

65IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examplesinterface GigabitEthernet5/2 switc

Page 59 - Routed Ports

66IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration ExamplesFigure 14 Routed Port Configuration

Page 60

67IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examplesredundancy main-cpu auto-sync sta

Page 61

68IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examplesinterface Vlan1 no ip address shut

Page 62

69IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples!crypto isakmp policy 1 encr 3des

Page 63

70IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples!!ip access-list extended AEO-101

Page 64 - Trunk Ports

71IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration ExamplesCatalyst Switch 2 (Trunk Port)The

Page 65

72IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examplesinterface GigabitEthernet5/1 switc

Page 66

73IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration ExamplesATM PortsNote This section applies

Page 67

7IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Hardware and Software Requirements–PA-MC-2T1: 2-port mult

Page 68

74IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples auto-sync standard!controller T3

Page 69 - ATM Ports

75IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples crypto connect vlan 6!interface S

Page 70

76IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples cdp enable!interface GigabitEther

Page 71

77IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration ExamplesCatalyst Switch 2 (ATM Port)The Ca

Page 72

78IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples multilink-group 1...!interface Mu

Page 73 - Catalyst Switch 2 (ATM Port)

79IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples ip address 10.10.20.254 255.255.2

Page 74

80IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration ExamplesCatalyst Switch 1 (Frame Relay Por

Page 75 - Frame Relay Ports

81IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examplesvlan 1 tb-vlan1 1002 tb-vlan2 1003

Page 76

82IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examplesinterface FastEthernet3/2 no ip ad

Page 77

83IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples clock source internal frame-relay

Page 78

8IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Hardware and Software RequirementsHardware RequirementsTh

Page 79

84IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples!crypto isakmp policy 1 encr 3des

Page 80

85IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples no ip address no fair-queue!inter

Page 81

86IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examplesno ip http serverno ip http secure

Page 82 - GRE Tunneling

87IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples flowcontrol send off switchport s

Page 83 - Catalyst Switch 2

88IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples switchport mode trunk cdp enable!

Page 84

89IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples!boot system flash sup-bootflash:!

Page 85

90IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples no ip address snmp trap link-stat

Page 86

91IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples!!no ip domain-lookup!!no mls ip m

Page 87

92IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples cdp enable!interface Vlan1 no ip

Page 88

93IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examplescrypto isakmp policy 1 encr 3des a

Page 89

9IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Front Panel DescriptionNote The FlexWAN module and the Op

Page 90 - Switch 1 Configuration

94IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples!line con 0line vty 0 4 login tran

Page 91

95IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples!!! Enables qos globallymls qos!cr

Page 92 - Switch 2 Configuration

96IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examples switchport trunk allowed vlan 1,1

Page 93

97IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Configuration Examplescrypto ipsec transform-set 3des_sh

Page 94 - Obtaining Documentation

98IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Regulatory Standards Complianceno ip http serverno ip ht

Page 95 - Documentation Feedback

99IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Obtaining DocumentationDocumentation CD-ROMCisco documen

Page 96 - Technical Assistance Center

100IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Obtaining Technical AssistanceObtaining Technical Assis

Page 97 - Cisco TAC Escalation Center

101IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Obtaining Additional Publications and InformationAll cu

Page 98

102IPSec VPN Acceleration Services Module Installation and Configuration Note78-14459-03 Rev C0Obtaining Additional Publications and Information• Inte

Comments to this Manuals

No comments