Configure Global Ikev2 Parameters; Enabling The Cookie Challenging Feature; Configuring The Ikev2 Dpd Feature; Configuring The Ikev2 Nat Keepalive Feature - HPE FlexFabric 5940 Series Security Configuration Manual

Hide thumbs Also See for FlexFabric 5940 Series:
Table of Contents

Advertisement

Configure global IKEv2 parameters

Enabling the cookie challenging feature

Enable cookie challenging on responders to protect them against DoS attacks that use a large
number of source IP addresses to forge IKE_SA_INIT requests.
To enable cookie challenging:
Step
1.
Enter system view.
2.
Enable IKEv2 cookie
challenging.

Configuring the IKEv2 DPD feature

IKEv2 DPD detects dead IKEv2 peers in periodic or on-demand mode.
Periodic IKEv2 DPD—Verifies the liveness of an IKEv2 peer by sending DPD messages at
regular intervals.
On-demand IKEv2 DPD—Verifies the liveness of an IKEv2 peer by sending DPD messages
before sending data.
Before the device sends data, it identifies the time interval for which the last IPsec packet
has been received from the peer. If the time interval exceeds the DPD interval, it sends a
DPD message to the peer to detect its liveliness.
If the device has no data to send, it never sends DPD messages.
If you configure IKEv2 DPD in both IKEv2 profile view and system view, the IKEv2 DPD settings in
IKEv2 profile view apply. If you do not configure IKEv2 DPD in IKEv2 profile view, the IKEv2 DPD
settings in system view apply.
To configure global IKEv2 DPD:
Step
1.
Enter system view.
2.
Configure global IKEv2
DPD.

Configuring the IKEv2 NAT keepalive feature

Configure this feature on the IKEv2 gateway behind the NAT device. The gateway then sends NAT
keepalive packets regularly to its peer to keep the NAT session alive, so that the peer can access the
device.
The NAT keepalive interval must be shorter than the NAT session lifetime.
This feature takes effect after the device detects the NAT device.
To configure the IKEv2 NAT keepalive feature:
Step
1.
Enter system view.
Command
system-view
ikev2 cookie-challenge number
Command
system-view
ikev2 dpd interval interval [ retry
seconds ] { on-demand | periodic }
Command
system-view
355
Remarks
N/A
By default, IKEv2 cookie
challenging is disabled..
Remarks
N/A
By default, global DPD is
disabled.
Remarks
N/A

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents