H3C S5830V2 Security Configuration Manual page 261

Hide thumbs Also See for S5830V2:
Table of Contents

Advertisement

Step
1.
Enter system view.
2.
Create an IPsec transform set
and enter its view.
Specify the security protocol
3.
for the IPsec transform set.
4.
Specify the security
algorithms.
5.
Specify the mode in which the
security protocol encapsulates
IP packets.
Command
system-view
ipsec transform-set
transform-set-name
protocol { ah | ah-esp | esp }
Specify the encryption
algorithm for ESP in non-FIPS
mode:
esp encryption-algorithm
{ 3des-cbc | aes-cbc-128 |
aes-cbc-192 | aes-cbc-256 |
des-cbc | null } *
Specify the encryption
algorithm for ESP in FIPS mode:
esp encryption-algorithm
{ aes-cbc-128 | aes-cbc-192 |
aes-cbc-256 } *
Specify the authentication
algorithm for ESP in non-FIPS
mode:
esp authentication-algorithm
{ md5 | sha1 } *
Specify the authentication
algorithm for ESP in FIPS mode:
esp authentication-algorithm
sha1
Specify the authentication
algorithm for AH in non-FIPS
mode:
ah authentication-algorithm
{ md5 | sha1 } *
Specify the authentication
algorithm for AH in FIPS mode:
ah authentication-algorithm
sha1
encapsulation-mode { transport |
tunnel }
247
Remarks
N/A
By default, no IPsec transform set
exists.
Optional.
By default, the IPsec transform set
uses ESP as the security protocol.
Configure at least one command.
By default, no security algorithm is
specified.
You can specify security algorithms
for a security protocol only when
the security protocol is used by the
transform set. For example, you
can specify the ESP-specific
security algorithms only when you
select ESP or AH-ESP as the security
protocol.
For ESP, you must specify both the
authentication and encryption
algorithms.
You can specify multiple
algorithms by using one command,
and the algorithm specified earlier
has a higher priority.
By default, the security protocol
encapsulates IP packets in tunnel
mode.
The transport mode applies only
when the source and destination IP
addresses of data flows match
those of the IPsec tunnel.
IPsec for IPv6 routing protocols
supports only the transport mode.

Advertisement

Table of Contents
loading

This manual is also suitable for:

S5820v2

Table of Contents