HP A6600 Configuration Manual page 267

Hide thumbs Also See for A6600:
Table of Contents

Advertisement

Configuration prerequisites
2.
Configure ACLs used for identifying protected traffic and IPsec proposals. ACLs are not required for
IPsec policies for an IPv6 protocol.
Configuration procedure
3.
To configure a manual IPsec policy:
To do...
1.
Enter system view.
2.
Create a manual IPsec policy and
enter its view.
3.
Assign an ACL to the IPsec policy.
4.
Assign an IPsec proposal to the
IPsec policy.
5.
Configure
Configure the local
the two
address of the tunnel.
ends of
the IPsec
tunnel.
Configure the remote
address of the tunnel.
6.
Configure the SPIs for the SAs.
Configure an
authentication key in
hexadecimal for AH.
Configure an
authentication key in
7.
Configure
characters for AH.
keys for
the SAs.
Configure a key in
characters for ESP.
Configure an
authentication key in
hexadecimal for ESP.
Configure an
encryption key in
hexadecimal for
ESP.
Command...
system-view
ipsec policy policy-name
seq-number manual
security acl acl-number
proposal proposal-name
tunnel local ip-address
tunnel remote ip-address
sa spi { inbound |
outbound } { ah | esp }
spi-number
sa authentication-hex {
inbound | outbound } ah
hex-key
sa string-key { inbound |
outbound } ah string-key
sa string-key { inbound |
outbound } esp string-key
sa authentication-hex {
inbound | outbound } esp
hex-key
sa encryption-hex {
inbound | outbound } esp
hex-key
255
Remarks
Required.
By default, no IPsec policy exists.
Not needed for IPsec policies to be
applied to IPv6 routing protocols
and required for other applications.
By default, an IPsec policy references
no ACL.
The ACL supports match criteria of
the VPN instance attribute.
Required.
By default, an IPsec policy references
no IPsec proposal.
Not needed for IPsec policies to be
applied to IPv6 routing protocols
and required for other applications.
Not configured by default.
Required.
Not configured by default.
Required.
Required.
Use either command.
Required.
Configure at least one command.
If you configure a key in characters
for ESP, the router automatically
generates an authentication key and
an encryption key for ESP.

Advertisement

Table of Contents
loading

Table of Contents