Vyatta Network OS Documentation

Learn how to install, configure and operate the Vyatta NOS, which helps drive our virtual networking & physical platforms portfolio.

Configure EAST

The connection from EAST to WEST only requires a minor change from that configured in the section Basic site-to-site connection.

  • WEST retains its fixed IP, so no modification is required to the remote peer IP address.
  • EAST has a dynamic local IP, so that must change. The dhcp-interface option specifies the DHCP client interface.

To configure this connection, perform the following steps on EAST in configuration mode.

Table 1. Specify that the local IP is dynamic
Step Command

Remove the existing local-address configuration so that doesn't conflict with the dhcp-interface configuration that will be set.

vyatta@EAST# delete security vpn ipsec site-to-site peer 192.0.2.1 local-address 

[edit]

Specify the DHCP client interface to use for the connection.

vyatta@EAST# set security vpn ipsec site-to-site peer 192.0.2.1 dhcp-interface dp0p1p1

[edit]

Commit the configuration.

vyatta@EAST# commit

View the configuration for the site-to-site connection.

vyatta@EAST# show security vpn ipsec site-to-site peer 192.0.2.1

    authentication
        mode pre-shared-secret
        pre-shared-secret test_key_1
    }
    default-esp-group ESP-1E
    dhcp-interface dp0p1p1
    ike-group IKE-1E
    tunnel 1 {
        local {
            prefix 192.168.60.0/24
        }
        remote {
            prefix 192.168.40.0/24
        }
    }

View data plane interface dp0p1p1 address configuration. It is set to dhcp which configures it as a DHCP client. This is the setting required by dhcp-interface.

vyatta@EAST# show interfaces dataplane dp0p1p1

 address dhcp