Applying An Ipsec Profile - HP 6125XLG Layer 3 - Ip Routing Configuration Manual

Blade switch
Hide thumbs Also See for 6125XLG:
Table of Contents

Advertisement

Applying an IPsec profile

To protect routing information and prevent attacks, OSPFv3 can authenticate protocol packets by using
an IPsec profile. For more information about IPsec profiles, see Security Configuration Guide.
Outbound OSPFv3 packets carry the Security Parameter Index (SPI) defined in the relevant IPsec profile.
A device uses the SPI carried in a received packet to match against the configured IPsec profile. If they
match, the device accepts the packet. Otherwise, the device discards the packet and will not establish a
neighbor relationship with the sending device.
You can configure an IPsec profile for an area, an interface, or a virtual link.
To implement area-based IPsec protection, configure the same IPsec profile on the routers in the
target area.
To implement interface-based IPsec protection, configure the same IPsec profile on the interfaces
between two neighboring routers.
To implement virtual link-based IPsec protection, configure the same IPsec profile on the two routers
connected over the virtual link.
If an interface and its area each have an IPsec profile configured, the interface uses its own IPsec
profile.
If a virtual link and area 0 each have an IPsec profile configured, the virtual link uses its own IPsec
profile.
To apply an IPsec profile to an area:
Step
1.
Enter system view.
2.
Enter OSPFv3 view.
3.
Enter OSPFv3 area view.
4.
Apply an IPsec profile to the
area.
To apply an IPsec profile to an interface:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Apply an IPsec profile to the
interface.
To apply an IPsec profile to a virtual link:
Step
1.
Enter system view.
2.
Enter OSPFv3 view.
Command
system-view
ospfv3 [ process-id | vpn-instance
vpn-instance-name ] *
area area-id
enable ipsec-profile profile-name
Command
system-view
interface interface-type
interface-number
ospfv3 ipsec-profile profile-name
Command
system-view
ospfv3 [ process-id | vpn-instance
vpn-instance-name ] *
368
Remarks
N/A
N/A
N/A
By default, no IPsec profile is
applied.
Remarks
N/A
N/A
By default, no IPsec profile is
applied.
Remarks
N/A
N/A

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

5920 series5900 series

Table of Contents