HP 5120 SI Series Security Configuration Manual page 372

Hide thumbs Also See for 5120 SI Series:
Table of Contents

Advertisement

Step
1.
Enter system view.
2.
Create an IKE peer and enter
IKE peer view.
3.
Specify the IKE negotiation
mode for phase 1.
4.
Specify the IKE proposals for
the IKE peer to reference.
5.
Configure the pre-shared key
for pre-shared key
authentication.
6.
Configure the PKI domain for
digital signature
authentication.
7.
Select the ID type for IKE
negotiation phase 1.
8.
Configure the names of the
two ends.
9.
Configure the IP addresses of
the two ends.
10.
Enable the NAT traversal
function for IPsec/IKE.
Command
system-view
ike peer peer-name
exchange-mode main
proposal proposal-number&<1-6>
pre-shared-key [ cipher | simple ]
key
certificate domain domain-name
id-type { ip | name | user-fqdn }
Specify a name for the local
security gateway:
local-name name
Configure the name of the
remote security gateway:
remote-name name
Specify an IP address for the
local gateway:
local-address ip-address
Configure the IP addresses of the
remote gateway:
remote-address { hostname
[ dynamic ] | low-ip-address
[ high-ip-address ] }
nat traversal
360
Remarks
N/A
N/A
Optional.
The default is main.
Optional.
By default, an IKE peer references
no IKE proposals, and, when
initiating IKE negotiation, it uses
the IKE proposals configured in
system view.
Configure either command
according to the authentication
method for the IKE proposal.
Optional.
ip by default.
Optional.
By default, no name is configured
for the local security gateway in
IKE peer view, and the security
gateway name configured by
using the ike local-name
command is used.
The remote gateway name
configured with remote-name
command on the local gateway
must be identical to the local
name configured with the
local-name command on the
peer.
Optional.
By default, it is the primary IP
address of the interface
referencing the security policy.
The remote IP address configured
with the remote-address
command on the local gateway
must be identical to the local IP
address configured with the
local-address command on the
peer.
Optional.
Disabled by default.

Advertisement

Table of Contents
loading

Table of Contents