RE: More IPSec questions.

From: Chuck Church (cchurch@xxxxxxxxxxxx)
Date: Thu Feb 22 2001 - 17:01:56 GMT-3


   
Lm,

    The people on this list will be much more willing to help you if you
send messages in plain text format. Other users on this list use Hotmail,
so there must be a way.

Chuck Church
CCNP, CCDP, MCNE, MCSE
Sr. Network Engineer
Magnacom Technologies
140 N. Rt. 303
Valley Cottage, NY 10989
845-267-4000 x218

-----Original Message-----
From: NoOne Important [mailto:lm_nguyen@hotmail.com]
Sent: Thursday, February 22, 2001 12:58 PM
To: fwells12@hotmail.com; ccielab@groupstudy.com
Subject: Re: More IPSec questions.

<html><DIV>
<P>COMMSERVER(config-crypto-map)#set ?<BR>&nbsp;
algorithm&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&
nbsp; Encryption/Decryption algorithms to use.<BR>&nbsp;
peer&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Allowed Encryption/Decryption peer.<BR>&nbsp;
security-association&nbsp; Security association parameters<BR>&nbsp;
transform-set&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Specify list
of transform sets in priority order</P>
<P>&nbsp;</P>
<P>My router can do that fine and i am only using ik2o3s-mz.120-7.T.bin</P>
<P>my suggestion is to erase the old config completely before try that
scenario on you routers.<BR><BR></P></DIV>
<DIV></DIV>
<DIV></DIV>&gt;From: "fwells12" <FWELLS12@HOTMAIL.COM>
<DIV></DIV>&gt;Reply-To: "fwells12" <FWELLS12@HOTMAIL.COM>
<DIV></DIV>&gt;To: <CCIELAB@GROUPSTUDY.COM>
<DIV></DIV>&gt;Subject: More IPSec questions.
<DIV></DIV>&gt;Date: Wed, 21 Feb 2001 21:33:29 -0800
<DIV></DIV>&gt;
<DIV></DIV>&gt;I have 12.1.5T Enterprise/FW IPSec 56 installed on my two
IPSec routers. =
<DIV></DIV>&gt; I am trying to get a handle on IPSec-manual keying
procedures. I have =
<DIV></DIV>&gt;just attempted once more to configure the following lab on
CCO:=20
<DIV></DIV>&gt;
<DIV></DIV>&gt;http://www.cisco.com/warp/public/707/manual.html
<DIV></DIV>&gt;
<DIV></DIV>&gt;Im my IOS I could not find the commands for any of the 'set =

<DIV></DIV>&gt;security-association' parameters. The only option I had that
had the =
<DIV></DIV>&gt;same parameters was 'set session-key'. I copied the configs
with the =
<DIV></DIV>&gt;exception of those parameters and it does not work thus far.
Does =
<DIV></DIV>&gt;anyone know if this is the equivalent of the 12.0 IOS command
'set =
<DIV></DIV>&gt;security association' etc, or am I completely overlooking
something =
<DIV></DIV>&gt;here?
<DIV></DIV>&gt;
<DIV></DIV>&gt;I would also like to find some more examples of IPSec Manual
Keying if =
<DIV></DIV>&gt;anyone knows any more please.
<DIV></DIV>&gt;
<DIV></DIV>&gt;Cheers
<DIV></DIV>&gt;



This archive was generated by hypermail 2.1.4 : Thu Jun 13 2002 - 10:28:57 GMT-3