Data transmitted between the central office and a branch, and between branches can be encrypted to increase data security. Binding an IPSec profile to DSVPN can dynamically establish an mGRE over IPSec tunnel.
After completing the preceding configuration, perform the following operations on the Hub and Spokes.
The system view is displayed.
An IPSec profile is created and the IPSec profile view is displayed.
An IKE peer is bound to the IPSec profile.
An IPSec proposal is bound to the IPSec profile.
The perfect forward secrecy (PFS) feature is used in IPSec negotiation.
By default, PFS is not used in IPSec negotiation.
If PFS is specified on the local end, you also need to specify PFS on the remote peer. The Diffie-Hellman groups specified on the two ends must be the same. Otherwise, the negotiation fails.
In the DSVPN IPSec protection scenario, the IPSec profile must be applied to a tunnel interface, not to a physical interface.
Return to the system view.
The tunnel interface view is displayed.
The tunnel encapsulation mode is configured.
The tunnel interface is bound to an IPSec profile.