
Contents
xiv
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
CHAPTER
22 Configuring ARP Inspection and Bridging Parameters 22-1
Configuring ARP Inspection 22-1
ARP Inspection Overview 22-1
Adding a Static ARP Entry 22-2
Enabling ARP Inspection 22-2
Customizing the MAC Address Table 22-3
MAC Address Table Overview 22-3
Adding a Static MAC Address 22-3
Setting the MAC Address Timeout 22-3
Disabling MAC Address Learning 22-4
Viewing the MAC Address Table 22-4
PART
3 Configuring VPN
CHAPTER
23 Configuring IPSec and ISAKMP 23-1
Tunneling Overview 23-1
IPSec Overview 23-2
Configuring ISAKMP 23-2
ISAKMP Overview 23-3
Configuring ISAKMP Policies 23-4
Enabling ISAKMP on the Outside Interface 23-5
Disabling ISAKMP in Aggressive Mode 23-6
Determining an ID Method for ISAKMP Peers 23-6
Enabling IPSec over NAT-T 23-7
Using NAT-T 23-7
Enabling IPSec over TCP 23-7
Waiting for Active Sessions to Terminate Prior to Reboot 23-8
Alerting Peers Before Disconnecting 23-8
Configuring Certificate Group Matching 23-9
Creating a Certificate Group Matching Rule and Policy 23-9
Using the Tunnel-group-map default-group Command 23-11
Configuring IPSec 23-11
Understanding IPSec Tunnels 23-11
Understanding Transform Sets 23-12
Defining Crypto Maps 23-12
Applying Crypto Maps to Interfaces 23-13
Using Interface Access Lists 23-13
Changing IPSec SA Lifetimes 23-15
Creating a Basic IPSec Configuration 23-16
Comentarios a estos manuales