3Com 3C13618 Command Reference Manual page 720

3com 3c13618: reference guide
Table of Contents

Advertisement

3Com Command Reference Guide — V1.00
Description
Using the ipsec policy (system view) command, you can create or modify an IPSec
policy, and enter the IPSec policy view. Using the undo ipsec policy (system view)
command, you can cancel the specified IPSec policy.
By default, no IPSec policy is set.
This command is applicable to the IPSec module of the operating system and crypto
card.
This command is used to create or modify an IPSec policy. To create an IPSec policy,
it is necessary to specify the negotiation mode (manual or isakmp). To modify the
IPSec policy, it is not necessary to specify a negotiation mode.
Once the IPSec policy is created, its negotiation mode can not be modified. For
example: if an IPSec policy is created in manual mode, it can not be changed to
isakmp mode, and this IPSec policy must be deleted before a new one can be
created.
IPSec policies with the same name constitute an IPSec policy group. The name and
sequence number are used together to define a unique IPSec policy. In an IPSec
policy group, 100 IPSec policies can be set at maximum. In an IPSec policy, the
smaller the sequence number of an IPSec policy is, the higher is its preference. Apply
an IPSec policy group at an interface means applying multiple IPSec policies in the
group, so that different data streams can be protected with different SAs.
The undo ipsec policy policy-name command is used to cancel an IPSec policy
whose
sequence-number command is used to cancel an IPSec policy whose name is
policy-name and sequence number is sequence-number.
If IKE is setting up an SA for IPSec policy negotiation, then the IPSec policy can not
be deleted.
If an IPSec policy is the only one in an IPSec policy group and this group has been
applied at the interface, then this group must be deleted from the interface (no more
applied at this interface) before the IPSec policy can be deleted.
For related commands, see ipsec policy (interface view), security acl, tunnel
local, tunnel remote, sa duration, sa inbound/outbound, proposal, display ipsec
policy.
Example
# Configure an IPSec policy whose name is newpolciy1, sequence number is 100,
and negotiation mode is isakmp.
[3Com]ipsec policy newpolicy1 100 isakmp
70
name
is
policy-name;
and
the
undo
ipsec
policy
policy-name

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

3c136123c136133c13616

Table of Contents