HP 3600 v2 Series Security Configuration Manual page 277

Hide thumbs Also See for 3600 v2 Series:
Table of Contents

Advertisement

directly connected neighbors or a RIPng process. For IPv6 BGP, the scope can be directly connected
neighbors or a neighbor group.
All SAs (both inbound and outbound) within the routed network scope must use the same SPI and
keys.
Configure the keys on all routers within the routed network scope in the same format. For example,
if you input the keys in hexadecimal format on one router, do so across the routed network scope.
Configuration procedure
2.
Follow these steps to configure a manual IPsec policy:
To do...
Enter system view
Create a manual IPsec policy and
enter its view
Assign an IPsec proposal to the
IPsec policy
Configure the
local address of
Configure the
the tunnel
two ends of the
IPsec tunnel
Configure the
remote address
of the tunnel
Configure the SPIs for the SAs
Configure an
authentication
key in
hexadecimal for
AH
Configure an
authentication
key in characters
for AH
Configure a key
Configure keys
in characters for
for the SAs
ESP
Configure an
authentication
key in
hexadecimal for
ESP
Configure an
encryption key in
hexadecimal for
ESP
Use the command...
system-view
ipsec policy policy-name
seq-number manual
proposal proposal-name
tunnel local ip-address
tunnel remote ip-address
sa spi { inbound | outbound }
{ ah | esp } spi-number
sa authentication-hex { inbound
| outbound } ah hex-key
sa string-key { inbound |
outbound } ah string-key
sa string-key { inbound |
outbound } esp string-key
sa authentication-hex { inbound
| outbound } esp hex-key
sa encryption-hex { inbound |
outbound } esp hex-key
266
Remarks
Required
By default, no IPsec policy exists.
Required
By default, an IPsec policy
references no IPsec proposal.
Not needed for IPsec policies to be
applied to IPv6 routing protocols
and required for other applications.
Not configured by default
Required
Not configured by default
Required
Required
Use either command
Required
Configure at least one command.
If you configure a key in characters
for ESP, the router automatically
generates an authentication key and
an encryption key for ESP.

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

A3100-48 v2

Table of Contents