HP 3600 v2 Series Security Configuration Manual page 281

Hide thumbs Also See for 3600 v2 Series:
Table of Contents

Advertisement

# Create an IPsec policy named policy001, specify the manual mode for it, and configure the SPIs of the
inbound and outbound SAs to 123456, and the keys for the inbound and outbound SAs using ESP to
abcdefg.
[SwitchC] ipsec policy policy001 10 manual
[SwitchC-ipsec-policy-manual-policy001-10] proposal tran1
[SwitchC-ipsec-policy-manual-policy001-10] sa spi outbound esp 123456
[SwitchC-ipsec-policy-manual-policy001-10] sa spi inbound esp 123456
[SwitchC-ipsec-policy-manual-policy001-10] sa string-key outbound esp abcdefg
[SwitchC-ipsec-policy-manual-policy001-10] sa string-key inbound esp abcdefg
[SwitchC-ipsec-policy-manual-policy001-10] quit
# Apply IPsec policy policy001 to the RIPng process.
[SwitchC] ripng 1
[SwitchC-ripng-1] enable ipsec-policy policy001
[SwitchC-ripng-1] quit
Verify the configuration
4.
After the configuration, Switch A, Switch B, and Switch C learns IPv6 routing information through RIPng.
SAs are set up successfully, and the IPsec tunnel between two peers is up for protecting the RIPng packets.
Using the display ripng command on Switch A, you will see the running status and configuration
information of the specified RIPng process. The output shows that IPsec policy policy001 is applied to this
process successfully.
<SwitchA> display ripng 1
RIPng process : 1
Preference : 100
Checkzero : Enabled
Default Cost : 0
Maximum number of balanced paths : 8
Update time
Suppress time :
Number of periodic updates sent : 186
Number of trigger updates sent : 1
IPsec policy name: policy001, SPI: 123456
Using the display ipsec sa command on Switch A, you will see the information about the inbound and
outbound SAs.
<SwitchA> display ipsec sa
===============================
Protocol: RIPng
===============================
-----------------------------
IPsec policy name: "policy001"
sequence number: 10
mode: manual
-----------------------------
connection id: 1
encapsulation mode: transport
perfect forward secrecy:
:
30 sec(s)
Timeout time
120 sec(s)
Garbage-Collect time :
270
:
180 sec(s)
120 sec(s)

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

A3100-48 v2

Table of Contents