R3303-HP HSR6800 Routers Layer 3 - IP Services Configuration Guide
313
# Specify the IP addresses of the VAM servers and set the pre-shared key.
[Spoke2-vam-client-name-dvpn1spoke2] server primary ip-address 192.168.1.22
[Spoke2-vam-client-name-dvpn1spoke2] server secondary ip-address 192.168.1.33
[Spoke2-vam-client-name-dvpn1spoke2] pre-shared-key simple 123
# Create a local user named dvpn1spoke2, setting the password as dvpn1spoke2.
[Spoke2-vam-client-name-dvpn1spoke2] user dvpn1spoke2 password simple dvpn1spoke2
[Spoke2-vam-client-name-dvpn1spoke2] client enable
[Spoke2-vam-client-name-dvpn1spoke2] quit
# Create a VAM client named dvpn2spoke2 for VPN 2.
[Spoke2] vam client name dvpn2spoke2
[Spoke2-vam-client-name-dvpn1spoke2] vpn 2
# Specify the IP addresses of the VAM servers and set the pre-shared key.
[Spoke2-vam-client-name-dvpn2spoke2] server primary ip-address 192.168.1.22
[Spoke2-vam-client-name-dvpn2spoke2] server secondary ip-address 192.168.1.33
[Spoke2-vam-client-name-dvpn2spoke2] pre-shared-key simple 456
# Create a local user named dvpn2spoke2, setting the password as dvpn2spoke2.
[Spoke2-vam-client-name-dvpn1spoke2] user dvpn2spoke2 password simple dvpn2spoke2
[Spoke2-vam-client-name-dvpn1spoke2] client enable
[Spoke2-vam-client-name-dvpn1spoke2] quit
3. Configure the IPsec profile
# Configure the IPsec transform set.
[Spoke2] ipsec transform-set vam
[Spoke2-ipsec-transform-set-vam] encapsulation-mode tunnel
[Spoke2-ipsec-transform-set-vam] transform esp
[Spoke2-ipsec-transform-set-vam] esp encryption-algorithm des
[Spoke2-ipsec-transform-set-vam] esp authentication-algorithm sha1
[Spoke2-ipsec-transform-set-vam] quit
# Configure the IKE peer.
[Spoke2] ike peer vam
[Spoke2-ike-peer-vam] pre-shared-key abcde
[Spoke2-ike-peer-vam] quit
# Configure the IPsec profile.
[Spoke2] ipsec profile vamp
[Spoke2-ipsec-profile-vamp] transform-set vam
[Spoke2-ipsec-profile-vamp] ike-peer vam
[Spoke2-ipsec-profile-vamp] sa duration time-based 600
[Spoke2-ipsec-profile-vamp] pfs dh-group2
[Spoke2-ipsec-profile-vamp] quit
4. Configure the DVPN tunnels:
# Configure tunnel interface Tunnel1 for VPN 1. Tunnel 1 uses UDP for encapsulation.
[Spoke2] interface tunnel 1
[Spoke2-Tunnel1] tunnel-protocol dvpn udp
[Spoke2-Tunnel1] vam client dvpn1spoke2
[Spoke2-Tunnel1] ip address 10.0.1.4 255.255.255.0
[Spoke2-Tunnel1] source gigabitethernet 3/0/1
[Spoke2-Tunnel1] ospf network-type broadcast