Cisco Cisco Packet Data Interworking Function (PDIF) Guía Para Resolver Problemas
IP Security
FA Services Configuration to Support IPSec ▀
Cisco ASR 5000 Series Enhanced Feature Configuration Guide ▄
OL-22982-01
FA Services Configuration to Support IPSec
This section provides instructions for configuring FA services to support IPSec.
These instructions assume that the FA service was previously configured and system is ready to serve as an FA.
Important:
This section provides the minimum instruction set for configuring an FA service to support IPSec on
the system. For more information on commands that configure additional parameters and options, refer to the Command
Line Interface Reference.
Line Interface Reference.
To configure the FA service to support IPSec:
Step 1
Modify FA service configuration by following the steps in the
Step 2
Verify your FA service configuration by following the steps in the
section.
Step 3
Save your configuration as described in the Verifying and Saving Your Configuration chapter.
Modifying FA service to Support IPSec
Use the following example to modify FA service to support IPSec on your system:
Notes:
<
> is the system context in which the FA service is configured to support IPSec.
<
> is name of the FA service for which you are configuring IPSec.
<
> is IP address of the HA service to which FA service will communicate on IPSec.
<
> is name of the preconfigured ISAKMP or a manual crypot map.
A default crypto map for the FA service to be used in the event that the AAA server returns an HA address that
is not configured as an ISAKMP peer HA.