Configuring An Ipsec Proposal - Huawei quidway s7700 Configuration Manual

Smart routing switch
Hide thumbs Also See for quidway s7700:
Table of Contents

Advertisement

Quidway S7700 Smart Routing Switch
Configuration Guide - SPU
When NAT traversal is enabled, local-id-type must be set to name.
Step 10 Run:
pre-shared-key key-string
The pre-shared key used by the local end and remote peer is configured.
If pre-shared key authentication is configured, you need to configure a pre-shared key for each
remote peer. The two ends of an IPSec tunnel must be configured with the same pre-shared key.
When pre-shared key authentication is configured, an authenticator must be configured.
Step 11 (Optional) Run:
remote-address [ vpn-instance vpn-instance-name ] ip-address
The IP address of the remote peer is configured.
Step 12 (Optional) Run:
sa binding vpn-instance vpn-instance-name
A VPN instance is associated with the SA.
By specifying the VPN instance that the remote end of the IPSec tunnel belongs to, you can
implement multi-instance IPSec connections. The configuration takes effect only on the initiator
of the tunnel. The initiator needs to obtain the outbound interface when sending packets. This
command specifies the VPN that the remote end of the IPSec tunnel belongs to. According to
the VPN, the tunnel initiator can obtain the outbound interface and send packets through the
outbound interface. The packets received by the remote peer contain the VPN attribute, so you
do not need to specify the VPN on the remote peer.
Step 13 Run:
remote-name name
The remote host name is configured (it is used only when the name authentication is used in
aggressive mode).
If IKEv2 is used, local-id-type must be set to ip and peer-id-type must be set to name, and the
remote-name parameter must be set.
----End

4.4.5 Configuring an IPSec Proposal

Both ends of the tunnel must be configured with the same security protocol, authentication
algorithm, encryption algorithm, and packet encapsulation mode.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
ipsec proposal proposal-name
An IPSec proposal is created and the IPSec proposal view is displayed.
Step 3 (Optional) Run:
Issue 01 (2011-07-15)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
4 IPSec Configuration
123

Advertisement

Table of Contents
loading

Table of Contents