Implementing Tunnel Interface-Based Ipsec; Configuration Task List - HP A6600 Configuration Manual

Hide thumbs Also See for A6600:
Table of Contents

Advertisement

To do...
3.
Enable IPsec RRI.
4.
Change the preference of
the static routes created by
IPsec RRI.
5.
Set a tag for the static
routes created by IPsec RRI.
NOTE:
IPsec RRI can work in both tunnel mode and transport mode.
When you change the route attributes, static IPsec RRI deletes all static routes it has created and
creates new static routes. In contrast, dynamic IPsec RRI applies the new attributes only to subsequent
static routes. It does not delete or modify static routes it has created.

Implementing tunnel interface-based IPsec

Configuration task list

This is the generic configuration procedure for implementing tunnel interface-based IPsec:
Configure an IPsec proposal to specify the security protocols, authentication and encryption
1.
algorithms, and encapsulation mode.
Configure an IPsec profile to associate data flows with the IPsec proposal and to specify the IKE
2.
peer parameters and the SA lifetime.
Configure an IPsec tunnel interface, and apply the IPsec profile to the interface. To enhance the
3.
encryption and decryption speed of the IPsec tunnel, bind the IPsec profile to one or more
encryption cards.
NOTE:
Because packets routed to the IPsec tunnel interface are all protected, the data protection scope, which
is required for IPsec policy configuration, is not needed in the IPsec profile.
Complete the following tasks to configure tunnel interface-based IPsec:
Task
Configuring an IPsec proposal
Configuring an IPsec profile
Configuring an IPsec tunnel interface
Command...
reverse-route [ remote-peer ip-
address [ gateway | static ] | static ]
reverse-route preference preference-
value
reverse-route tag tag-value
263
Remarks
Required.
Disabled by default.
To enable static IPsec RRI,
specify the static keyword. If the
keyword is not specified,
dynamic IPsec RRI is enabled.
Optional.
60 by default.
Optional.
0 by default.
Remarks
Required
An IPsec proposal for the IPsec
tunnel interface to reference
supports tunnel mode only.
Required
Required

Advertisement

Table of Contents
loading

Table of Contents