Pfs - HP 5920 Command Reference Manual

Table of Contents

Advertisement

Syntax
local-address { ipv4-address | ipv6 ipv6-address }
undo local-address
Default
The primary IPv4 address of the interface to which the IPsec policy is applied is used as the local IPv4
address, and the first IPv6 address of the interface to which the IPsec policy is applied is used as the local
IPv6 address.
Views
IPsec policy view, IPsec policy template view
Predefined user roles
network-admin
Parameters
ipv4-address: Specifies the local IPv4 address for the IPsec tunnel.
ipv6 ipv6-address: Specifies the local IPv6 address for the IPsec tunnel.
Usage guidelines
The remote IP address on the IKE negotiation initiator must be the same as the local address on the IKE
negotiation responder.
Examples
# Configure the local address 1.1.1.1 for the IPsec tunnel.
<Sysname> system-view
[Sysname] ipsec policy map 1 isakmp
[Sysname-ipsec-policy-isakmp-map-1] local-address 1.1.1.1
Related commands
remote-address

pfs

Use pfs to enable the perfect forward secrecy (PFS) feature for an IPsec transform set, used for IKE
negotiation.
Use undo pfs to restore the default.
Syntax
In non-FIPS mode:
pfs { dh-group1 | dh-group2 | dh-group5 | dh-group14 | dh-group24 }
undo pfs
In FIPS mode:
pfs dh-group14
350

Advertisement

Table of Contents
loading

This manual is also suitable for:

59005920 series5900 series

Table of Contents