peer

crypto-map-ipsec-isakmp-instance

Configures the IKEv1 or IKEv2 peer for the auto site-to-site VPN tunnel or remote VPN client. The peer device can be specified either by its hostname or by its IP address. A maximum of three peers can be configured.

Supported in the following platforms:

  • Access Points — AP505i, AP510i/e, AP560i/h
  • Service Platforms — NX5500, NX7500, NX9500, NX9600, VX9000

Syntax

peer <1-3> [ikev1|ikev2] <IKEv1/IKEv2-PEER-NAME>

Parameters

peer <1-3> [ikev1|ikev2] <IKEv1/IKEv2-PEER-NAME>
peer <1-3> Creates a new peer and configures the peer‘s priority level. Peer ‘1‘ is the primary peer, and peer ‘3‘ is redundant.
ikev1 <IKEv1-PEER-NAME> Configures an IKEv1 peer
  • <IKEv1-PEER-NAME> – Specify the IKEv1 peer‘s name.
ikev2<IKEv2-PEER-NAME> Configures an IKEv2 peer
  • <IKEv2-PEER-NAME> – Specify the IKEv2 peer‘s name.

Example

Site-to-site tunnel:

rfs4000-229D58(config-device-00-23-68-22-9D-58-cryptomap-test#1)#peer 1 ikev2 ikev2Peer1

rfs4000-229D58(config-device-00-23-68-22-9D-58-cryptomap-test#1)#show context
 crypto map test 1 ipsec-isakmp
  peer 1 ikev2 ikev2Peer1
  local-endpoint-ip 192.168.13.10
  ip nat crypto
rfs4000-229D58(config-device-00-23-68-22-9D-58-cryptomap-test#1)#

Remote VPN client:

rfs4000-229D58(config-device-00-23-68-22-9D-58-cryptomap-test#2)#peer 1 ikev1 Re
moteIKEv1Peer1

rfs4000-229D58(config-device-00-23-68-22-9D-58-cryptomap-test#2)#show context
 crypto map test 2 ipsec-isakmp dynamic
  peer 1 ikev1 RemoteIKEv1Peer1
  local-endpoint-ip 157.235.204.62
rfs4000-229D58(config-device-00-23-68-22-9D-58-cryptomap-test#2)#