HP MSR Series Configuration Manual page 317

Hpe flexnetwork msr router series
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

Step
1.
Enter system view.
2.
Create an IPsec policy
template and enter its view.
3.
(Optional.) Configure a
description for the IPsec
policy template.
4.
(Optional.) Specify an ACL
for the IPsec policy template.
5.
Specify IPsec transform sets
for the IPsec policy template.
6.
Specify an IKE profile for the
IPsec policy template.
7.
Specify an IKEv2 profile for
the IPsec policy template.
8.
(Optional.) Specify the local
IP address of the IPsec
tunnel.
9.
(Optional.) Specify the
remote IP address of the
IPsec tunnel.
Command
system-view
ipsec { ipv6-policy-template |
policy-template } template-name
seq-number
description text
security acl [ ipv6 ] { acl-number |
name acl-name } [ aggregation |
per-host ]
transform-set
transform-set-name&<1-6>
ike-profile profile-name
ikev2-profile profile-name
local-address { ipv4-address |
ipv6 ipv6-address }
remote-address { [ ipv6 ]
host-name | ipv4-address | ipv6
ipv6-address }
302
Remarks
N/A
By default, no IPsec policy
template exists.
By default, no description is
configured.
By default, no ACL is specified for
an IPsec policy template.
You can specify only one ACL for
an IPsec policy template.
By default, no IPsec transform set
is specified for an IPsec policy
template.
By default, no IKE profile is
specified for an IPsec policy
template.
You can specify only one IKE
profile for an IPsec policy template
and the IKE profile cannot be
used by another IPsec policy
template or IPsec policy.
For more information about IKE
profiles, see
"Configuring
By default, no IKEv2 profile is
specified for an IPsec policy
template.
You can specify only one IKEv2
profile for an IPsec policy
template.
For more information about IKEv2
profiles, see
"Configuring
By default, the local IPv4 address
of IPsec tunnel is the primary IPv4
address of the interface to which
the IPsec policy is applied, and
the local IPv6 address of the
IPsec tunnel is the first IPv6
address of the interface to which
the IPsec policy is applied.
The local IP address specified by
this command must be the same
as the IP address used as the
local IKE identity.
In a VRRP network, the local IP
address must be the virtual IP
address of the VRRP group to
which the IPsec-applied interface
belongs.
By default, the remote IP address
of the IPsec tunnel is not
specified.
IKE."
IKEv2."

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents