HP MSR2000 Configuration Manual page 204

Hide thumbs Also See for MSR2000:
Table of Contents

Advertisement

[DeviceB-ipsec-policy-isakmp-use1-10] ike-profile profile1
[DeviceB-ipsec-policy-isakmp-use1-10] quit
# Apply IPsec policy use1 to interface Ethernet 1/1.
[DeviceB-Ethernet1/1] ipsec apply policy use1
# Configure a static route to the subnet where Host A resides.
[DeviceB] ip route-static 10.1.1.0 255.255.255.0 1.1.1.1
Verifying the configuration
When there is traffic between subnets 10.1.1.0/24 and 10.1.2.0/24, IKE negotiation is triggered.
# Display the IKE proposal configuration on Device A and Device B. Because no IKE proposal is
configured, the command displays the default IKE proposal.
[DeviceA] display ike proposal
Priority Authentication Authentication Encryption
----------------------------------------------------------------------------
default
PRE-SHARED-KEY
[DeviceB] display ike proposal
Priority Authentication Authentication Encryption
----------------------------------------------------------------------------
default
PRE-SHARED-KEY
# Display the IKE SA on Device A.
[DeviceA] display ike sa
Connection-ID
------------------------------------------------------------------
1
Flags:
RD--READY RL--REPLACED FD-FADING
# Display the IPsec SAs generated on Device A.
[DeviceA] display ipsec sa
-------------------------------
Interface: Ethernet1/1
-------------------------------
-----------------------------
IPsec policy: map1
Sequence number: 10
Mode: isakmp
-----------------------------
Tunnel id: 0
Encapsulation mode: tunnel
Perfect forward secrecy:
Path MTU: 1456
Tunnel:
local
remote address: 2.2.2.2
method
algorithm
SHA1
method
algorithm
SHA1
Remote
2.2.2.2
address: 1.1.1.1
Diffie-Hellman Duration
algorithm
AES-CBC-128
Group 1
Diffie-Hellman Duration
algorithm
AES-CBC-128
Group 1
Flag
DOI
RD
IPSEC
193
group
(seconds)
86400
group
(seconds)
86400

Advertisement

Table of Contents
loading

This manual is also suitable for:

Msr3000Msr4000

Table of Contents