EasyManuals Logo
Home>Cisco>Network Router>ASR 1002

Cisco ASR 1002 User Manual

Cisco ASR 1002
72 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #36 background imageLoading...
Page #36 background image
Page 36 of 72
4.6.3 NAT Traversal
For successful NAT traversal over an IOS-XE NAT device for an IPsec connection between two
IOS-XE peers, the following configuration needs to be used (Also refer to Chapter 7 of [21])
On an IOS NAT device (router between the IPsec endpoints):
config terminal
ip nat service list <ACL-number> ESP spi-match
access-list <ACL-number> permit <protocol> <local-range> <remote-range>
end
On each IOS peer (IPsec router endpoints):
config terminal
crypto ipsec nat-transparency spi-matching
end
4.6.4 X.509 Certificates
The TOE may be configured by the privileged administrators to use X.509v3 certificates to
authenticate IPsec peers. Both RSA and ECDSA certificates are supported. Creation of these
certificates and loading them on the TOE is covered in the section “How to Configure
Certificate Enrollment for a PKI” in [22], and a portion of the TOE configuration for use of these
certificates follows below.
4.6.4.1 Creation of the Certificate Signing Request
The certificate signing request for the TOE will be created using the RSA or ECDSA key pair
and the domain name configured in Section 3.3.1 above.
In order for a certificate signing request to be generated, the TOE must be configured with a,
hostname and trustpoint.
1. Enter configure terminal mode:
Device # configure terminal
2. Specify the hostname: hostname name
Device(config)# hostname asrTOE
3. Configure the trustpoint: crypto pki trustpoint trustpoint-name
Device (config)#crypto pki trustpoint ciscotest
4. Configure an enrollment method: enrollment [terminal, url url]
Device (ca-trustpoint)#enrollment url http://192.168.2.137:80

Table of Contents

Other manuals for Cisco ASR 1002

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco ASR 1002 and is the answer not in the manual?

Cisco ASR 1002 Specifications

General IconGeneral
Ethernet LANYes
Cabling technology10/100/1000Base-T(X)
Networking standardsIEEE 802.3
Ethernet LAN data rates10, 100, 1000 Mbit/s
Ethernet interface typeGigabit Ethernet
DHCP client-
Supported network protocolsBGP, GRE, OSPF, DVMRP, EIGRP, IS-IS, IGMPv3, PIM-SM, PIM-SSM
Ethernet LAN (RJ-45) ports4
Security algorithmsSSH
VPN tunnels quantity8000
SafetyUL60950-1 CSA, C22.2 No. 60950-1-03, EN 60950-1, IEC 60950-1, AS/NZS 60950.1
CertificationFCC 47CFR15 Class A AS/NZS CISPR 22 CISPR 22 Class A EN55022 Class A ICES-003 Class A VCCI Class A CNS-13438 Class A EN61000-3-2 EN61000-3-3
Internal memory4096 MB
AC input voltage85 - 264 V
Power source typeAC
AC input frequency50 - 60 Hz
Power consumption (typical)560 W
Operating altitude0 - 3048 m
Storage temperature (T-T)0 - 50 °C
Operating temperature (T-T)0 - 40 °C
Storage relative humidity (H-H)5 - 95 %
Operating relative humidity (H-H)5 - 90 %
Product colorGray
Rack capacity2U
Weight and Dimensions IconWeight and Dimensions
Depth461 mm
Width437.4 mm
Height89 mm
Weight- g

Related product manuals