how to get Tunnel Peer IP address
how to get Tunnel Peer IP address
Tags:
#VPN
| Company Information | Perfecto Mobile | Customer |
| Company Name | Perfecto Mobile | British Telecom |
| Data Center Location (where VPN tunnel is terminated) | us-east-1 | Belfast |
| VPN tunnel configuration requirements | Perfecto Mobile | Customer |
| VPN device (manufacturer) | pfSense | tplink |
| VPN device (models) | v2.3.4 | ER605 |
| Tunnel Peer IP address | ? | |
| IKE Phase 1 ISAKMP Parameters | Perfecto Mobile | Customer |
| IKE Version | IKEv1 (Preferred) IKEv2 |
IKEV1 |
| Authentication method | Pre-shared secret (Will be Shared via SMS) | Pre-shared secret |
| ISAKMP Encryption Algorithm | AES 256 bit AES 128 bit 3DES |
AES 256 bit |
| ISAKMP Data Integrity Hash Algorithm | SHA-1 | SHA-1 |
| ISAKMP Diffie-Hellman Key Exchange Group | Group 5 for AES 256 bit Group 5 for AES 128 bit Group 2 for 3DES |
Group 5 for AES 256 bit |
| ISAKMP SA Lifetime | 86400 seconds | 86400 seconds |
| ISAKMP Negotiation Mode | Main | Main |
| ISAKMP Identity | IP address | IP address |
| ISAKMP Dead Peer Detection (DPD) | Enabled, keep-alive threshold 10, retry 2 | 10 |
| ISAKMP NAT-T | Enabled | Enabled |
| ISAKMP XAUTH | Disabled | Disabled |
| IKE Phase 2 IPSec Parameters | Perfecto Mobile | Customer |
| IKE Version | IKEv1 Transform Set (Preferred) IKEv2 Proposal |
IKEv1 Transform Set |
| IPSEC SA Encapsulation | ESP | ESP |
| IPSEC SA Encryption | AES 256 bit AES 128 bit 3DES |
AES 256 bit |
| IPSEC SA Authentication Method | SHA1 | SHA1 |
| IPSEC SA PFS | No PFS | none |
| IPSEC SA Lifetime | 3600 seconds | 3600 seconds |
| Encryption Domains | Perfecto Mobile | Customer |
| Encryption Domain (crypto access lists) - MCM | 198.160.7.240/32 | ? |
| Encryption Domain (crypto access lists) - VOD/VAS
|
198.160.7.241/32 | ? |
| Encryption Domain (crypto access lists) - STS | 198.160.7.242/32 | ? |
| Network Engineer Contact Information | Perfecto Mobile | Customer |
This is the configuration I have to set in ER 605 Tplink VPN router but confused how to get Tunnel Peer IP address and how to set below encryption domains
| Encryption Domain (crypto access lists) - MCM |
| Encryption Domain (crypto access lists) - VOD/VAS
|
| Encryption Domain (crypto access lists) - STS |
1 Accepted Solution

IKEV1
AES 256 bit
Group 5 for AES 256 bit
IKEv1 Transform Set
No PFS