H3C S5830V2 Security Configuration Manual page 265

Hide thumbs Also See for S5830V2:
Table of Contents

Advertisement

Step
5.
Specify IPsec transform sets
for the IPsec policy.
6.
Specify an IKE profile for the
IPsec policy.
7.
Specify the local IP address of
the IPsec tunnel.
8.
Specify the remote IP address
of the IPsec tunnel.
9.
Set the IPsec SA lifetime.
10.
(Optional.) Set the IPsec SA
idle timeout.
11.
Return to system view.
12.
Set the global SA lifetime.
13.
(Optional.) Enable the global
IPsec SA idle timeout function,
and set the global SA idle
timeout.
Configuring an IKE-based IPsec policy by referencing an IPsec policy template
The configurable parameters for an IPsec policy template are the same as those when you directly
configure an IKE-based IPsec policy. The difference is that more parameters are optional for an IPsec
policy template. Except the IPsec transform sets and the IKE profile, all other parameters are optional.
Command
transform-set
transform-set-name&<1-6>
ike-profile profile-name
local-address { ipv4-address | ipv6
ipv6-address }
remote-address { [ ipv6 ]
host-name | ipv4-address | ipv6
ipv6-address }
sa duration { time-based seconds |
traffic-based kilobytes }
sa idle-time seconds
quit
ipsec sa global-duration
{ time-based seconds |
traffic-based kilobytes }
ipsec sa idle-time seconds
251
Remarks
By default, the IPsec policy
references no IPsec transform set.
By default, the IPsec policy
references no IKE profile, and it
uses the IKE parameters configured
in system view for negotiation.
An IPsec policy can reference only
one IKE profile and it cannot
reference any IKE profile that is
already referenced by other IPsec
policies or IPsec policy templates.
For more information about IKE
profiles, see
"Configuring
By default, the local IPv4 address
of IPsec tunnel is the primary IPv4
address of the interface to which
the IPsec policy is applied, and the
local IPv4 address of the IPsec
tunnel is the first IPv6 address of the
interface to which the IPsec policy
is applied.
The local IP address specified by
this command must be the same as
the IP address used as the local IKE
identity.
By default, the remote IP address of
the IPsec tunnel is not specified.
By default, the global SA lifetime is
used.
By default, the global SA idle
timeout is used.
N/A
By default, the time-based SA
lifetime is 3600 seconds, and the
traffic-based SA lifetime is
1843200 kilobytes.
By default, the global IPsec SA idle
timeout function is disabled.
IKE."

Advertisement

Table of Contents
loading

This manual is also suitable for:

S5820v2

Table of Contents