HPE FlexNetwork 10500 Series Security Configuration Manual page 360

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

IPsec policy template. Except the IPsec transform sets and the IKE profile, all other parameters are
optional.
A device using an IPsec policy that is configured by using an IPsec policy template cannot initiate an
SA negotiation, but it can respond to a negotiation request. The parameters not defined in the
template are determined by the initiator. For example, in an IPsec policy template, the ACL is
optional. If you do not specify an ACL, the IPsec protection range has no limit. So the device accepts
all ACL settings of the negotiation initiator. When the remote end's information (such as the IP
address) is unknown, the IPsec policy configured by using this method allows the remote end to
initiate negotiations with the local end.
To configure an IKE-based IPsec policy by using an IPsec policy template:
Step
1.
Enter system view.
2.
Create an IPsec policy
template and enter its view.
3.
(Optional.) Configure a
description for the IPsec
policy template.
4.
(Optional.) Specify an ACL
for the IPsec policy template.
5.
Specify IPsec transform sets
for the IPsec policy template.
6.
Specify an IKE profile for the
IPsec policy.
7.
Specify an IKEv2 profile for
the IPsec policy template.
Command
system-view
ipsec { ipv6-policy-template |
policy-template } template-name
seq-number
description text
security acl { acl-number | name
acl-name } [ aggregation |
per-host ]
transform-set
transform-set-name&<1-6>
ike-profile profile-name
ikev2-profile profile-name
343
Remarks
N/A
By default, no IPsec policy
templates exist.
By default, no description is
configured.
By default, no ACL is specified for
an IPsec policy template.
You can specify only one ACL for
an IPsec policy template.
By default, no IPsec transform
sets are specified for an IPsec
policy template.
By default, no IKE profile is
specified for the IPsec policy
template.
You can specify only one IKE
profile for an IPsec policy template
and the IKE profile cannot be
used by another IPsec policy
template or IPsec policy.
For more information about IKE
profiles, see
"Configuring
By default, no IKEv2 profile is
specified for the IPsec policy
template.
You can specify only one IKEv2
profile for an IPsec policy
template.
For more information about IKEv2
profiles, see
"Configuring
IKE."
IKEv2."

Advertisement

Table of Contents
loading

Table of Contents