VMware, Inc. 135
Appendix B vShield Edge VPN Configuration Examples
Phase 1: Main Mode Transactions
ThefollowingtransactionsoccurinsequencebetweenthevShieldEdgeandaCiscoVPNdeviceinMain
Mode.
1vShieldEdgetoCisco
proposal:encrypt3des‐cbc,sha,psk,group5(group2)
DPDenabled
2CiscotovShieldEdge
containsproposalchosenbyCisco
IftheCiscodevicedoesnotacceptanyoftheparametersthevShieldEdgesentinstepone,theCisco
devicesendsthemessagewithflagNO_PROPOSAL_CHOSENandterminatesthenegotiation.
3vShieldEdgetoCisco
DHkeyandnonce
4CiscotovShieldEdge
DHkeyandnonce
5vShieldEdgetoCisco(Encrypted)
includeID
(PSK)
6CiscotovShieldEdge(Encrypted)
includeID(PSK)
IftheCiscodevicefindsthatthePSKdoesnʹtmatch,theCiscodevicesendsamessagewithflag
INVALID_ID_INFORMATION;Phase1fails.
Phase 2: Quick Mode Transactions
ThefollowingtransactionsoccurinsequencebetweenthevShieldEdgeandaCiscoVPNdeviceinQuick
Mode.
1vShieldEdgetoCisco
vShieldEdgeproposesPhase2policytothepeer.Forexample:
Aug 26 12:16:09 weiqing-desktop pluto[5789]: "s1-c1" #2: initiating Quick Mode
PSK+ENCRYPT+TUNNEL+PFS+UP+IKEv2ALLOW {using isakmp#1 msgid:d20849ac
proposal=3DES(3)_192-SHA1(2)_160 pfsgroup=OAKLEY_GROUP_MODP1024}
2CiscotovShieldEdge
CiscodevicesendsbackNO_PROPOSAL_CHOSENifitdoesnotfindanymatchingpolicyfortheproposal.
Otherwise,theCIscodevicesendsthesetofparameterschosen.
3vShieldEdgetoCisco
Tofacilitatedebugging,youcanturnonIPSecloggingonthevShieldEdgeandenablecryptodebugon
Cisco(debug crypto isakmp <level>)
Configuring the vShield Edge VPN Parameters
AvShieldEdgesupportssite‐to‐siteIPSecVPNbetweenavShieldEdgeandremotesites.
To configure VPN on a vShield Edge
1InthevSphereClient,gotoInventory>Networking.
2 SelectaninternalportgroupthatisprotectedbyavShieldEdge.
3ClickthevShieldEdgetab.
Komentarze do niniejszej Instrukcji