
GT IPsec Setup Guide
© 2012 ExaDigm, Inc. Page 8 of 13 Rev. 1/1212
mtu inside 1500
mtu outside 1500
icmp unreachable rate-limit 1 burst-size 1
no asdm history enable
arp timeout 14400
nat (inside,any) source static obj-192.168.166.0 obj-192.168.166.0
destination static obj-192.168.155.0 obj-192.168.155.0 no-proxy-arp
!
object network obj_any
nat (inside,outside) dynamic interface
access-group inside_access_in in interface inside
access-group outside_access_in in interface outside
route outside 0.0.0.0 0.0.0.0 74.212.223.225 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat
0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect
0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
timeout floating-conn 0:00:00
dynamic-access-policy-record DfltAccessPolicy
user-identity default-domain LOCAL
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec ikev2 ipsec-proposal AES256
protocol esp encryption aes-256
protocol esp integrity sha-1 md5
crypto ipsec ikev2 ipsec-proposal AES192
protocol esp encryption aes-192
protocol esp integrity sha-1 md5
crypto ipsec ikev2 ipsec-proposal AES
protocol esp encryption aes
protocol esp integrity sha-1 md5
crypto ipsec ikev2 ipsec-proposal 3DES
protocol esp encryption 3des
protocol esp integrity sha-1 md5
crypto ipsec ikev2 ipsec-proposal DES
protocol esp encryption des
protocol esp integrity sha-1 md5
crypto ipsec ikev2 ipsec-proposal gtikev2
protocol esp encryption aes-256 aes-192 aes 3des des
protocol esp integrity sha-1 md5
crypto ipsec security-association lifetime seconds 7200
crypto map gtmap 1 match address vzw_l2l
crypto map gtmap 1 set peer 166.142.29.80
crypto map gtmap 1 set ikev2 ipsec-proposal 3DES DES AES AES192 AES256
crypto map gtmap 1 set security-association lifetime seconds 7200
crypto map gtmap interface outside
crypto ikev2 policy 10
encryption aes-256 aes-192 aes 3des des
integrity sha md5
group 5 2 1
prf sha md5
lifetime seconds 7200
crypto ikev2 enable outside
telnet 192.168.166.0 255.255.255.0 inside