!
! Century Systems NXR-650 Series ver 21.2.0 (build 5/09:02 27 06 2019)
!    DIP-SW : 1:off 2:off 3:off 4:off
!
hostname NXR_A
telnet-server enable
http-server enable
!
!
!
!
!
!
!
ipv6 forwarding
fast-forwarding enable
!
!
!
!
!
ipsec x509 enable
ipsec x509 ca-certificate nxr pem
ipsec x509 certificate nxra pem
ipsec x509 private-key nxra key pem
ipsec x509 private-key nxra password nxrapass
ipsec x509 crl nxr pem
ipsec eap identity string nxrb password nxrbpass
!
l2tp udp source-port 40001
!
!
ipsec local policy 1
 address ip
 x509 certificate nxra
!
!
ipsec isakmp policy 1
 description NXR_B
 version 2
 authentication remote eap-md5
 authentication local rsa-sig
 keepalive 30 3 periodic clear
 hash sha256
 encryption aes128
 group 5
 lifetime 86400
 remote address ip any
 remote identity fqdn nxrb
 local policy 1
!
!
ipsec tunnel policy 1
 description NXR_B
 negotiation-mode responder
 set transform esp-aes128 esp-sha256-hmac
 set pfs group5
 set key-exchange isakmp 1
 set sa lifetime 28800
 match address ipsec_acl
!
!
interface tunnel 1
 no ip address
 ip tcp adjust-mss auto
 tunnel mode ipsec ipv4
 tunnel protection ipsec policy 1
!
interface ethernet 0
 ip address 192.168.10.1/24
!
interface ethernet 1
 ip address 203.0.113.1/30
 ipsec policy 1
!
interface ethernet 2
 no ip address
!
dns
 service enable
!
!
syslog
 local enable
 exit-syslog
!
!
!
system led ext 0 signal-level mobile 0
!
!
!
!
!
!
!
ip route 192.168.20.0/24 tunnel 1
ip route 192.168.20.0/24 null 254
ip route 0.0.0.0/0 203.0.113.2
!
!
!
ipsec access-list ipsec_acl ip any any
!
!
!
end