Configuring Ipsec For Ipv6 Routing Protocols; Configuration Task List; Configuring A Manual Ipsec Profile - HP VSR1000 Security Configuration Manual

Virtual services router
Table of Contents

Advertisement

Step
5.
(Optional.) Set the tag value
for the static routes created by
IPsec RRI.

Configuring IPsec for IPv6 routing protocols

Configuration task list

Complete the following tasks to configure IPsec for IPv6 routing protocols:
Tasks at a glance
(Required.)
(Required.)
(Required.) Applying the IPsec profile to an IPv6 routing protocol (see Layer 3—IP Routing Configuration Guide)
(Optional.)
(Optional.)

Configuring a manual IPsec profile

An IPsec profile is similar to an IPsec policy. The difference is that an IPsec profile is uniquely identified
by a name and it does not support ACL configuration. An IPsec profile defines the IPsec transform set
used for protecting data flows, and specifies SPIs and the keys used by the SAs.
When you configure a manual IPsec profile, make sure the IPsec profile configuration at the two tunnel
ends meets the following requirements:
The IPsec transform set referenced by the IPsec profile at the two tunnel ends must have the same
security protocol, encryption and authentication algorithms, and packet encapsulation mode.
The local inbound and outbound IPsec SAs must have the same SPI and key.
The IPsec SAs on the devices in the same scope must have the same key. The scope is defined by
protocols. For OSPF, the scope consists of OSPF neighbors or an OSPF area. For RIPng, the scope
consists of directly-connected neighbors or a RIPng process. For BGP, the scope consists of BGP
peers or a BGP peer group.
The keys for the IPsec SAs at the two tunnel ends must be configured in the same format. For
example, if the key at one end is entered as a string of characters, the key on the other end must also
be entered as a string of characters.
To configure a manual IPsec profile:
Step
1.
Enter system view.
Configuring an IPsec transform set
Configuring a manual IPsec profile
Enabling logging of IPsec packets
Configuring SNMP notifications for IPsec
Command
system-view
Command
reverse-route tag tag-value
192
Remarks
The default value is 0.
Remarks
N/A

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents