Enterasys Networks XSR CLI Router User Manual


 
Interface VPN Commands
XSR CLI Reference Guide 14-123
ip multicast-redirect - NativeIPSectunnelsattachedtoVPNinterfaceswillnoteasily
forwardmulticasttrafficmulticastpacketredirectiontothe unicastaddressoftheremote
tunnelendpoint.Refertopage14126forthecommanddefinition.
ip address ‐DefinesanexplicitIPaddressonthisvirtualinterface.Refertopage5151for
thecommanddescription.
ip nat source‐Controls NATonpacketsenteringthisVPNport.Refertopage5186forthe
commanddescription.
ip ripcommands‐ConfiguresRIPoptionsontheVPNinterface.Refertothe“Configuring
theInternetProtocol”onpage 583chapterfordescriptionsofRIPcommands.
ip split-horizon‐SetsRIPsplithorizonoptionsontheVPNport.Refertopage5130for
thecommanddescription.
ip unnumbered ‐CreatesanunnumberedVPNinterface.Refertopage5166forthe
commanddescription.
service-policy‐AttachesapolicymaptoanVPNoutputorinputinterface.Refertopage
14127forthecommanddescription.
tunnel‐CreatesatunneltoaVPNgateway.Refertopage14127forthecommand
description.
SomeVPNconfigurationpropertiesareassociatedwithaspecificnetworkinterfaceorrequire
creationofvirtualnetworkinterfacesthatrepresenttunnels.
ThissectiondefinestheVPNrelatedsubcommandsprovidedbythe
interface vpncommand.
AVPNinterfaceisaspecialformofavirtualnetworkinterfacethatrepresentsanIPSectunnel
withEZIPSecautomaticconfiguration,L2TP,orPPTPtunnel(s).ItisrequiredtosupportVPN
tunnelswhichhaveIPaddresses.Thesetunnelsshouldnotbeconfusedwithtunnelmodein
IPSec.Atunnel
onaVPNinterfacehasIPaddressesatbothendsandisusedbytherouting
subsystemlikeanyothernetworkinterface.
AVPNinterfacecanbeconfiguredasfollows:
interface vpn 4 point-to-point
interface vpn 3 multi-point
PointtoPointinterfacesareusedwhendefininganoutboundtunneltoanothergateway.This
interfacetype,inconjunctionwiththe
tunnelcommand,issuitedtoinitiatingoutboundtunnels
toothersecuritygatewaysthatsupportdynamicIPaddressassignment.
EachoutboundtunnelisassociatedwithaVPNinterface.Thatinterface,whichcanbeconfigured
intotheroutingprotocols,isconsidereddownuntilthetunnelhasconnectedandanIPaddress
hasbeenobtained
fromtheremoteVPNgateway.
Note: The tunnel command is a sub-command of interface vpn.
Note: Only one tunnel may be defined per point-to-point VPN interface.