Contents 7
Configuring the pre-shared key for IKE 122
Enabling or disabling PFS 123
Configuring IKE proposal 123
Configuring OCSP for the IKE policy 128
Configuring IPsec for site-to-site VPN 129
Creating an IPsec policy 129
Configuring anti-replay 129
Enabling or disabling the IPsec policy entry 130
Specifying the IP stream on which to apply IPsec 130
Configuring DH prime modulus group for PFS 131
Configuring IPsec proposal 132
Configuring remote access IKE policies 137
Creating an IKE policy for remote access VPN 137
Configuring an IKE proposal for remote access VPN 146
Configuring remote access IPsec policies 151
Creating an IPsec policy for remote access VPN 151
Specifying the IP stream on which to apply IPsec for remote access VPN 152
Configuring DH prime modulus group for PFS 153
Configuring IPsec proposal template for remote access VPN 154
Enabling the dynamic IPsec policy 158
Configuring L2TP server for L2TP remote access 159
Creating the L2TP remote access interface 159
Configuring IP address for the L2TP access interface 159
Configuring IPsec protection for the L2TP access interface 160
Configuring client parameters for L2TP remote access 161
Configuring user parameters for L2TP remote access 161
Shutting down the L2TP access interface 162
Configuring dead peer detection keepalive 162
Enabling dead peer detection 162
Configuring the keepalive retry interval 163
Configuring the keepalive transmit-interval 163
Configuring PMTU 163
Configuring DF bit 163
Configuring the MTU threshold value 164
Configuring processing of unsecured ICMP messages 164
Configuring CA trustpoint 165
Configuring the certificate enrollment method 165
Configuring parameters for the certificate request 166
Configuring certificate password 169
Authenticating the CA and importing a CA certificate 169
Generating a certificate request for enrollment 170
Manually importing a self certificate 171
Manually importing an OCSP Responder certificate 171
Nortel Secure Router 4134
Security — Configuration and Management
NN47263-600 01.02 Standard
10.0 3 August 2007
Copyright © 2007, Nortel Networks
.