Ipsec; Local Priority - HPE FlexNetwork HSR6800 Security Command Reference

Hide thumbs Also See for FlexNetwork HSR6800:
Table of Contents

Advertisement

Examples
# Configure the number of the GDOI KS group abc as 123456.
<Sysname> system-view
[Sysname]gdoi ks group abc
[Sysname-gdoi-ks-group-abc] identity number 123456
Related commands
identity address
gdoi ks group

ipsec

Use ipsec to create an IPsec policy for the GDOI KS group and enter GDOI KS IPsec policy view.
Use undo ipsec to delete an IPsec policy for the GDOI KS group.
Syntax
ipsec sequence-number
undo ipsec sequence-number
Default
No IPsec policy is created for a GDOI KS group.
Views
GDOI KS group view
Default command level
2: System level
Parameters
sequence-number: Specifies a sequence number for the IPsec policy, in the range of 1 to 65535.
Usage guidelines
You can create multiple IPsec policies for a GDOI KS group. An IPsec policy with a smaller number
has a higher priority. A KS can send multiple IPsec policies to GMs at a time, and GMs use the IPsec
policies from the one with the highest priority.
Deleting an IPsec policy from a GDOI KS group also deletes the TEK that corresponds to that IPsec
policy.
Examples
# Create IPsec policy 10 for the GDOI KS group abc and enter its view.
<Sysname> system-view
[Sysname] gdoi ks group abc
[Sysname-gdoi-ks-group-abc] ipsec 10
[Sysname-gdoi-ks-group-abc-ipsec-10]
Related commands
gdoi ks group

local priority

Use local priority to configure the GDOI KS local priority.
Use undo local priority to restore the default.
488

Advertisement

Table of Contents
loading

Table of Contents