Huawei AR1200 series Configuration Manual page 306

Enterprise routers
Hide thumbs Also See for AR1200 series:
Table of Contents

Advertisement

Huawei AR1200 Series Enterprise Routers
Configuration Guide - VPN
ike-proposal proposal-number
An IKE proposal is configured.
Step 5 (Optional) Run:
local-id-type { ip | name }
The local ID type is configured.
By default, the IP address of the local end is used as the local ID.
Step 6 (Optional) Run:
local-address address
The IP address of the local end is configured.
By default, the local end address is the IP address of the interface bound to the IPSec policy.
Step 7 (Optional) Run:
peer-id-type { ip | name }
The peer ID type is configured.
By default, the IP address of the local end is used as the local ID.
The peer-id-type command is valid only when IKEv2 is used.
Step 8 (Optional) Run:
nat traversal
NAT traversal is enabled.
When NAT traversal is enabled, local-id-type must be set to name.
Step 9 (Optional) Run:
pre-shared-key key-string
The pre-shared key used by the local end and remote peer is configured.
If pre-shared key authentication is configured, configure a pre-shared key for each remote peer.
The two ends of an IPSec tunnel must use the same pre-shared key.
When pre-shared key authentication is configured, an authenticator must be configured.
Step 10 Run:
remote-address { ip-address | host-name }
The IP address or the domain name of the remote peer is configured.
Step 11 (Optional) Run:
sa binding vpn-instance vpn-instance-name
A VPN instance is associated with the SA.
By specifying the VPN instance that the remote end of the IPSec tunnel belongs to, you can
implement multi-instance IPSec connections. The configuration takes effect only on the initiator
of the IPSec tunnel. The initiator needs to obtain the outbound interface when sending packets.
This command specifies the VPN that the remote end belongs to. According to the VPN, the
tunnel initiator can obtain the outbound interface and send packets through the outbound
Issue 01 (2012-04-20)
NOTE
In the IPSec policy template mode, you do not need to run the remote-address command.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
5 IPSec Configuration
295

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ar3200 series

Table of Contents