Establishing An Ipsec Tunnel Manually; Establishing The Configuration Task - Huawei quidway s7700 Configuration Manual

Smart routing switch
Hide thumbs Also See for quidway s7700:
Table of Contents

Advertisement

Quidway S7700 Smart Routing Switch
Configuration Guide - SPU

4.3 Establishing an IPSec Tunnel Manually

You can establish IPSec tunnels manually when the network topology is simple.

4.3.1 Establishing the Configuration Task

Before establishing an IPSec tunnel manually, familiarize yourself with the applicable
environment, complete the pre-configuration tasks, and obtain the required data.
Applicable Environment
Data flows must be authenticated to ensure data transmission security. In the scenarios
demanding high security, data flows must be authenticated and encrypted. In such a scenario,
you can configure IPSec on the device that initiates the IPSec service and the device that
terminates the IPSec service.
You can establish IPSec tunnels manually when the network topology is simple.
Pre-configuration Tasks
Before establishing an IPSec tunnel manually, complete the following tasks:
l
l
Data Preparation
To establish an IPSec tunnel manually, you need the following data.
No.
1
2
3
4
Issue 01 (2011-07-15)
Setting parameters of the link-layer protocol and IP addresses for the interfaces to ensure
that the link-layer protocol on the interfaces is Up
Configuring routes between the source and the destination
Data
Parameters of an advanced ACL
IPSec proposal name, security protocol, authentication algorithm of AH,
authentication algorithm and encryption algorithm of ESP, and packet
encapsulation mode
Name and sequence number of the IPSec policy, local and peer IP addresses of
the tunnel, inbound and outbound SPIs of AH, inbound and outbound SPIs of
ESP, inbound and outbound authentication keys of AH (character strings),
inbound and outbound authentication keys of ESP (character strings), inbound
and outbound authentication keys of AH (hexadecimal numbers), inbound and
outbound authentication keys of ESP (hexadecimal numbers), inbound and
outbound encryption keys of ESP (hexadecimal numbers), (optional) VPN
instance name
Type and number of the interface to which the IPSec policy group is applied
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
4 IPSec Configuration
114

Advertisement

Table of Contents
loading

Table of Contents