Applying An Ipsec Policy To An Interface; Checking The Configuration - Huawei quidway s7700 Configuration Manual

Smart routing switch
Hide thumbs Also See for quidway s7700:
Table of Contents

Advertisement

Quidway S7700 Smart Routing Switch
Configuration Guide - SPU

4.4.9 Applying an IPSec policy to an interface

An interface can use only one IPSec policy group. An IPSec policy group created through IKE
negotiation can be applied to multiple interfaces.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 (Optional) Run:
ipsec policy policy-name seq-number isakmp template template-name
The IPSec policy template is used to create an IPSec policy.
Step 3 Run:
interface interface-type interface-number
The interface view is displayed.
Step 4 Run:
ipsec policy policy-name
An IPSec policy group is applied to the interface.
Only one IPSec policy group can be applied on an interface. An IPSec policy group can be
applied to multiple interfaces.
After the configuration, the packets transmitted between two ends of the IPSec tunnel trigger
the establishment of an SA through the IKE negotiation. In automatic triggering mode, the SA
is established immediately after the IKE negotiation succeeds. In traffic-based triggering mode,
the SA is established only after data flows matching the IPSec policy are sent from the interface.
After IKE negotiation succeeds and the SA is established, the data flows between two ends of
the tunnel are encrypted and then transmitted.
----End

4.4.10 Checking the Configuration

After an IPSec tunnel is established through IKE negotiation, you can view information about
the SA, configuration of the IKE peer, and configuration of the IKE proposal.
Prerequisite
The configurations required to establish an IPSec tunnel through IKE negotiation are complete.
Procedure
l
l
Issue 01 (2011-07-15)
Run the display ike sa command to view information about the SAs established through
IKE negotiation.
Run the display ike peer [ name peer-name ] [ verbose ] command to view the
configuration of a specified IKE peer or all IKE peers.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
4 IPSec Configuration
128

Advertisement

Table of Contents
loading

Table of Contents