Configuring Ipsec For Ipv6 Routing Protocols; Configuration Task List; Configuring A Manual Ipsec Profile - HPE FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Configuring IPsec for IPv6 routing protocols

Configuration task list

Complete the following tasks to configure IPsec for IPv6 routing protocols:
Tasks at a glance
(Required.)
(Required.)
(Required.) Applying the IPsec profile to an IPv6 routing protocol (see Layer 3—IP Routing Configuration
Guide)
(Optional.)
Enabling logging of IPsec packets
(Optional.)
Configuring SNMP notifications for IPsec

Configuring a manual IPsec profile

A manual IPsec profile is similar to a manual IPsec policy. The difference is that an IPsec profile is
uniquely identified by a name and it does not support ACL configuration. A manual IPsec profile
specifies the IPsec transform set used for protecting data flows, and the SPIs and keys used by the
SAs.
When you configure a manual IPsec profile, make sure the IPsec profile configuration at both tunnel
ends meets the following requirements:
The IPsec transform set specified in the IPsec profile at the two tunnel ends must have the
same security protocol, encryption and authentication algorithms, and packet encapsulation
mode.
The local inbound and outbound IPsec SAs must have the same SPI and key.
The IPsec SAs on the devices in the same scope must have the same key. The scope is defined
by protocols. For OSPF, the scope consists of OSPF neighbors or an OSPF area. For RIPng,
the scope consists of directly-connected neighbors or a RIPng process. For BGP, the scope
consists of BGP peers or a BGP peer group.
The keys for the IPsec SAs at the two tunnel ends must be configured in the same format. For
example, if the key at one end is entered as a string of characters, the key on the other end
must also be entered as a string of characters.
To configure a manual IPsec profile:
Step
1.
Enter system view.
2.
Create a manual IPsec
profile and enter its view.
3.
(Optional.) Configure a
description for the IPsec
profile.
Configuring an IPsec transform set
Configuring a manual IPsec profile
Command
system-view
ipsec profile profile-name manual
description text
350
Remarks
N/A
By default, no IPsec profile exists.
The manual keyword is not
needed if you enter the view of an
existing IPsec profile.
By default, no description is
configured.

Advertisement

Table of Contents
loading

Table of Contents