HPE FlexNetwork 10500 Series Security Configuration Manual page 359

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Step
6.
Specify an IKE profile for the
IPsec policy.
7.
Specify an IKEv2 profile for
the IPsec policy.
8.
Specify the local IP address
of the IPsec tunnel.
9.
Specify the remote IP
address of the IPsec tunnel.
10. (Optional.) Set the IPsec SA
lifetime.
11. (Optional.) Set the IPsec SA
idle timeout.
12. (Optional.) Enable the Traffic
Flow Confidentiality (TFC)
padding feature.
13. Return to system view.
14. Set the global SA lifetime.
15. (Optional.) Enable the global
IPsec SA idle timeout
feature, and set the global
SA idle timeout.
Configuring an IKE-based IPsec policy by using an IPsec policy template
The configurable parameters for an IPsec policy template are the same as those when you directly
configure an IKE-based IPsec policy. The difference is that more parameters are optional for an
Command
ike-profile profile-name
ikev2-profile profile-name
local-address ipv4-address
remote-address { host-name |
ipv4-address }
sa duration { time-based
seconds | traffic-based
kilobytes }
sa idle-time seconds
tfc enable
quit
ipsec sa global-duration
{ time-based seconds |
traffic-based kilobytes }
ipsec sa idle-time seconds
342
Remarks
By default, no IKE profile is
specified for an IPsec policy.
You can specify only one IKE
profile for an IPsec policy.
For more information about IKE
profiles, see
"Configuring
By default, no IKEv2 profile is
specified for the IPsec policy.
You can specify only one IKEv2
profile for an IPsec policy.
For more information about IKEv2
profiles, see
"Configuring
By default, the local IPv4 address
of IPsec tunnel is the primary IPv4
address of the interface to which
the IPsec policy is applied, and
the local IPv6 address of the
IPsec tunnel is the first IPv6
address of the interface to which
the IPsec policy is applied.
The local IP address specified by
this command must be the same
as the IP address used as the
local IKE identity.
In a VRRP network, the local IP
address must be the virtual IP
address of the VRRP group to
which the IPsec-applied interface
belongs.
By default, the remote IP address
of the IPsec tunnel is not
specified.
By default, the global SA lifetime
is used.
By default, the global SA idle
timeout is used.
By default, the TFC padding
feature is disabled.
N/A
By default, the time-based SA
lifetime is 3600 seconds, and the
traffic-based SA lifetime is
1843200 kilobytes.
By default, the global IPsec SA
idle timeout feature is disabled.
IKE."
IKEv2."

Advertisement

Table of Contents
loading

Table of Contents