Create the connection to WEST
This task defines a site-to-site connection to WEST. In this example:
- This connection is configured with a single tunnel:
- Tunnel 1 communicates between 192.168.60.0/24 on EAST and 192.168.40.0/24 on WEST, using ESP group ESP-1E.
- EAST uses IP address 192.0.2.33 on dp0p1p1.
- WEST uses IP address 192.0.2.1 on dp0p1p2.
- The IKE group is IKE-1E.
- The authentication mode is pre-shared secret. The pre-shared secret is test_key_1.
To configure this connection, perform the following steps on EAST in configuration mode.
Create the node for WEST and set the authentication mode.
Navigate to the node for the peer for easier editing.
Provide the string that will be used to generate encryption keys.
Specify the default ESP group for all tunnels.
Specify the IKE group.
Identify the IP address on this Vyatta router to be used for this connection.
Create a tunnel configuration, and provide the local subnet for this tunnel.
Provide the remote subnet for the tunnel.
Return to the top of the configuration tree.
Now commit the configuration.
View the configuration for the site-to-site connection.
View data plane interface dp0p1p1 address configuration. local-address is set to this address.