Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


Step 1-1 Identify IPSec Peers

Sep 27,2009 by alperen

image

Step 1-1 Identify IPSec Peers

An important part of defining a comprehensive IPSec policy is to identify the IPSec peer pairs that must be configured. In the chapter scenario, expanded in Figure 10-2, each remote site will connect only to the Main Office router and, therefore, requires only simple configuration. The Cisco router at the Main Office must be configured for peer communications with each of the remote sites and telecommuter(s). Each peer must support IPSec. Because many different types of peer devices exist, it’s important to identify all potential peers and determine their VPN capabilities. Possible peer devices could include, but aren’t limited to, the following:

It’s important to recognize that IPSec features supported and default settings can vary between Cisco product families, as well as versions of the operating system (OS) being used. This is most important for the Main Office router in the scenario because it must be able to establish common IKE and IPSec policies with each remote device. This also demonstrates why many companies limit the number of devices supported by defining standards for telecommuters or branch offices.

The result of this analysis might be a table like the following:

Location

Device

Version (or OS)

Main Office

Cisco 7100 router

12.2(8)T with FW and VPN

Telecommuters (24)

Cisco 900 Cable/DSL router

12.2(8)T with FW and VPN supports 3DES

Mobile users (16)

Cisco VPN Software Client

v3.6-3DES

Branch offices (80) North America

Cisco 2600/3600 routers

12.2(8)T with FW and VPN supports 3DES

Branch offices (20) Europe/Africa

Cisco 2600/3600 routers

12.2(8)T with FW and VPN supports DES only

Manufacturing (1)

Cisco PIX 525 Firewall

OS v6.2-3DES


178 times read

Related news

» The VPN Concentrators in LAN-to-LAN VPNs
by alperen posted on Dec 31,2009
» IPSec Support in Cisco Systems Products
by alperen posted on Sep 27,2009
» Standards Supported
by alperen posted on Oct 30,2009
» Cisco VPN 3000 LAN-to-LAN Networks Review
by alperen posted on Dec 31,2009
» IPSec over NAT-T
by alperen posted on Dec 31,2009
Did you enjoy this article?
(total 0 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author