Configure Global Ikev2 Parameters; Enabling The Cookie Challenging Feature; Configuring The Ikev2 Dpd Feature - HP MSR Series Configuration Manual

Hpe flexnetwork msr router series
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

Step
4.
Configure the information
for identifying the IKEv2
peer.
5.
Configure a pre-shared key
for the peer.

Configure global IKEv2 parameters

Enabling the cookie challenging feature

Enable cookie challenging on responders to protect them against DoS attacks that use a large
number of source IP addresses to forge IKE_SA_INIT requests.
To enable cookie challenging:
Step
1.
Enter system view.
2.
Enable cookie challenging.

Configuring the IKEv2 DPD feature

IKEv2 DPD detects dead IKEv2 peers in periodic or on-demand mode.
Periodic DPD—Verifies the liveness of an IKEv2 peer by sending DPD messages at regular
intervals.
On-demand DPD—Verifies the liveness of an IKEv2 peer by sending DPD messages before
sending data.
Before the device sends data, it identifies the time interval for which the last IPsec packet
has been received from the peer. If the time interval exceeds the DPD interval, it sends a
DPD message to the peer to detect its liveliness.
If the device has no data to send, it never sends DPD messages.
If you configure IKEv2 DPD in both IKEv2 profile view and system view, the IKEv2 DPD settings in
IKEv2 profile view apply. If you do not configure IKEv2 DPD in IKEv2 profile view, the IKEv2 DPD
settings in system view apply.
To configure global IKEv2 DPD:
Command
To configure a host name for
the peer:
hostname host-name
To configure a host IP
address or address range for
the peer:
address { ipv4-address
[ mask | mask-length ] | ipv6
ipv6-address
[ prefix-length ] }
To configure an ID for the
peer:
identity { address
{ ipv4-address | ipv6
{ ipv6-address } } | fqdn
fqdn-name | email
email-string | key-id
key-id-string }
pre-shared-key [ local | remote ]
{ ciphertext | plaintext } string
Command
system-view
ikev2 cookie-challenge number
370
Remarks
By default, no hostname, host IP
address, address range, or identity
information is configured for an
IKEv2 peer.
You must configure different IP
addresses/address ranges for
different peers.
By default, an IKEv2 peer does not
have a pre-shared key.
Remarks
N/A
By default, IKEv2 cookie
challenging is disabled..

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents