Configuring IPSec VPNs

Because simple misconfiguration is the cause of many issues that arise with IPSec VPNs, this section discusses basic configuration of both site-to-site and remote access VPNs. This section also assumes that IKE is being used for SA negotiation.

Note that it is also possible to manually configure IPSec session keys on IPSec peers. This method of configuration, however, is comparatively rare, and is, therefore, not discussed further in this chapter.

NOTE

For more information concerning manual configuration of IPSec session keys, see the following URL:

http://www.cisco.com/warp/customer/707/manual.shtml

Similarly, although there are three methods of peer authentication during IKE negotiation, only preshared keys and digital ...

Get Troubleshooting Virtual Private Networks now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.