Huawei quidway s7700 Configuration Manual page 150

Smart routing switch
Hide thumbs Also See for quidway s7700:
Table of Contents

Advertisement

Quidway S7700 Smart Routing Switch
Configuration Guide - SPU
[SPU-ike-proposal-1] authentication-algorithm md5
[SPU-ike-proposal-1] quit
Step 3 Configure the local IDs and IKE peers on SPUs of SwitchA and SwitchB.
# Configure the local ID and IKE peer on the SPU of SwitchA.
[SPU] ike local-name huawei01
[SPU] ike peer spub v1
[SPU-ike-peer-spub] exchange-mode aggressive
[SPU-ike-peer-spub] ike-proposal 1
[SPU-ike-peer-spub] local-id-type name
[SPU-ike-peer-spub] pre-shared-key huawei
[SPU-ike-peer-spub] remote-name huawei02
[SPU-ike-peer-spub] remote-address 202.38.162.1
[SPU-ike-peer-spub] local-address 202.38.163.1
[SPU-ike-peer-spub] quit
# Configure the local ID and IKE peer on the SPU of SwitchB.
[SPU] ike local-name huawei02
[SPU] ike peer spua v1
[SPU-ike-peer-spua] exchange-mode aggressive
[SPU-ike-peer-spua] ike-proposal 1
[SPU-ike-peer-spua] local-id-type name
[SPU-ike-peer-spua] pre-shared-key huawei
[SPU-ike-peer-spua] remote-name huawei01
[SPU-ike-peer-spua] remote-address 202.38.163.1
[SPU-ike-peer-spua] local-address 202.38.162.1
[SPU-ike-peer-spua] quit
Run the display ike peer command on the SPUs of SwitchA and SwitchB to view the
configuration of the IKE peers. Take the display on the SPU of SwitchA as an example.
[SPU] display ike peer name spub verbose
----------------------------------------
----------------------------------------
Step 4 Configure ACLs on the SPUs of SwitchA and SwitchB to define the data flows to be protected.
# Configure an ACL on the SPU of SwitchA.
[SPU] acl number 3101
[SPU-acl-adv-3101] rule permit ip source 10.1.1.0 0.0.0.255 destination 10.1.2.0
0.0.0.255
[SPU-acl-adv-3101] quit
# Configure an ACL on the SPU of SwitchB.
[SPU] acl number 3101
Issue 01 (2011-07-15)
NOTE
In aggressive mode, you need to configure the IP address of the remote peer (remote-address).
Peer name
: spub
Exchange mode
: aggressive on phase 1
Pre-shared-key
: huawei
Local ID type
: name
DPD
: Disable
DPD mode
: Periodic
DPD idle time
: 20
DPD retrans int
: 5
DPD retry limit
: 5
Peer ip address
: 202.38.162.1
VPN name
:
Local ip address : 202.38.163.1
Remote name
: huawei02
Nat-traversal
: Disable
Configured IKE version
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
: Version one
4 IPSec Configuration
139

Advertisement

Table of Contents
loading

Table of Contents