Huawei AR1200 series Configuration Manual page 344

Enterprise routers
Hide thumbs Also See for AR1200 series:
Table of Contents

Advertisement

Huawei AR1200 Series Enterprise Routers
Configuration Guide - VPN
----------------------------------------
Step 5 Create IPSec proposals on RouterA and RouterB.
# Create an IPSec proposal on RouterA.
[Huawei] ipsec proposal tran1
[Huawei-ipsec-proposal-tran1] transform ah-esp
[Huawei-ipsec-proposal-tran1] ah authentication-algorithm sha1
[Huawei-ipsec-proposal-tran1] esp authentication-algorithm sha1
[Huawei-ipsec-proposal-tran1] esp encryption-algorithm 3des
[Huawei-ipsec-proposal-tran1] quit
# Create an IPSec proposal on RouterB.
[Huawei] ipsec proposal tran1
[Huawei-ipsec-proposal-tran1] transform ah-esp
[Huawei-ipsec-proposal-tran1] ah authentication-algorithm sha1
[Huawei-ipsec-proposal-tran1] esp authentication-algorithm sha1
[Huawei-ipsec-proposal-tran1] esp encryption-algorithm 3des
[Huawei-ipsec-proposal-tran1] quit
Run the display ipsec proposal command on RouterA and RouterB to view the configuration
of the IPSec proposal. Take the display on RouterA as an example.
[Huawei] display ipsec proposal
Number of Proposals: 1
IPSec proposal name: tran1
Encapsulation mode: Tunnel
Transform
AH protocol
ESP protocol
Step 6 Create IPSec profiles on RouterA and RouterB.
# Create an IPSec profile on RouterA.
[Huawei]
[Huawei-ipsec-profile-profile1] proposal tran1
[Huawei-ipsec-profile-profile1] ike-peer spub
[Huawei-ipsec-profile-profile1] quit
# Create an IPSec profile on RouterB.
[Huawei]
[Huawei-ipsec-profile-profile1] proposal tran1
[Huawei-ipsec-profile-profile1] ike-peer spua
Issue 01 (2012-04-20)
Peer name
Pre-shared-key
proposal
Local ID type
DPD
DPD mode
DPD idle time
DPD retransmit interval
DPD retry limit
Peer ID type
Host name
Peer IP address
VPN name
Local IP address
Remote name
Nat-traversal
Configured IKE version
Auto-configure
PKI realm
Inband OCSP
: ah-esp-new
: Authentication SHA1-HMAC-96
: Authentication SHA1-HMAC-96
Encryption
ipsec profile profile1
ipsec profile profile2
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
: spub
: huawei
: 1
:
: Disable
: Periodic
: 30
: 15
: 3
:
:
:
:
: 202.138.163.1
:
: Disable
: Version two
: Disable
: NULL
: Disable
3DES
5 IPSec Configuration
333

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ar3200 series

Table of Contents