Technical Specs

Table Of Contents
!
crypto ikev2 redirect gateway init
crypto ikev2 proposal FlexVPN_IKEv2_Proposal
encryption aes-cbc-128
integrity sha1
group 5
!
crypto ikev2 policy FLexVPN_IKEv2_Policy
proposal FlexVPN_IKEv2_Proposal
!
!
crypto ikev2 profile FlexVPN_IKEv2_Profile
match certificate FlexVPN_Cert_Map
identity local dn
authentication remote rsa-sig
authentication local rsa-sig
pki trustpoint LDevID
aaa authorization group cert list FlexVPN_Author FlexVPN_Author_Policy
virtual-template 1
!
!
crypto ikev2 cluster
port 2000
standby-group group1
slave priority 90
slave max-session 10
no shutdown
!
!
cdp run
!
ip tftp source-interface GigabitEthernet0/0/3
ip ssh version 2
!
!
!
!
!
!
!
!
crypto ipsec transform-set AES_128_SHA1 esp-aes esp-sha-hmac
mode transport
!
crypto ipsec profile FlexVPN_IPsec_Profile
set transform-set AES_128_SHA1
set ikev2-profile FlexVPN_IKEv2_Profile
responder-only
!
!
!
!
!
!
!
!
interface Loopback0
ip address 20.0.0.3 255.255.0.0
ipv6 address 2003:20::1/128
ipv6 address 2333::1/64
ipv6 enable
ipv6 ospf 1 area 1
!
interface GigabitEthernet0/0/0
78
REVIEW DRAFT - CISCO CONFIDENTIAL