DMVPN with IPsec Phase 3: Difference between revisions
Appearance
mNo edit summary |
mNo edit summary |
||
| Line 77: | Line 77: | ||
<b>Step 3</b>: configure DMVPN Phase 2 parameters: | <b>Step 3</b>: configure DMVPN Phase 2 parameters: | ||
1. Encryption algorithm - AES 128 | |||
2. Hash algorithm - SHA256 | |||
3. PFS group -MODP3072 | |||
<br>[[File: | <br>[[File:Hub phase2 fix.png|alt=|border]] | ||
---- | ---- | ||
<b>Step 4</b>: configure DMVPN NHRP parameters: | <b>Step 4</b>: configure DMVPN NHRP parameters: | ||
In the NHRP parameters section, it is important to enable REDIRECT option, which is essential to our Phase 3 configuration. | In the NHRP parameters section, it is important to enable '''REDIRECT''' option, which is essential to our Phase 3 configuration. | ||
<br>[[File: | <br>[[File:Redirect.png|alt=|border]] | ||
---- | ---- | ||
<b>Step 5</b>: save changes | <b>Step 5</b>: save changes | ||
| Line 99: | Line 99: | ||
<b>Step 1</b>: enable BGP and configure General section: | <b>Step 1</b>: enable BGP and configure General section: | ||
1. Enable vty | |||
2. Set AS to 65000 | |||
3. Set BGP router ID for easier management. | |||
4. Set announcement network(s). Routes to these networks will be shared over BGP. We used 192.168.1.0/24 | |||
5. "NHRP routes" selection should be applied under the "Redistribution options" section | |||
<br>[[File: | <br>[[File:Hub bgp.png|alt=|border]] | ||
---- | ---- | ||