Match Local Address (Ike Profile View) - HP FlexFabric 7900 Series Command Reference Manual

Security
Hide thumbs Also See for FlexFabric 7900 Series:
Table of Contents

Advertisement

Usage guidelines
Use this command to specify which address or interface can use the IKE keychain for IKE negotiation.
Specify the local address configured in IPsec policy view (using the local-address command) for this
command. If no local address is configured, specify the IP address of the interface that references the
IPsec policy.
You can specify up to six IKE keychains for an IKE profile. An IKE keychain specified earlier has a higher
priority. To give an IKE keychain a higher priority, you can configure this command for the keychain. For
example, suppose you configured IKE keychain A before configuring IKE keychain B, and you configured
the peer ID 2.2.0.0/16 for IKE profile A and the peer ID 2.2.2.0/24 for IKE profile B. For peer 2.2.2.2,
IKE keychain A is preferred because IKE profile A was configured earlier. To use IKE profile B for the peer,
you can use this command to restrict the application scope of IKE keychain B to address 2.2.2.2.
Examples
# Create IKE keychain key1.
<Sysname> system-view
[Sysname] ike keychain key1

match local address (IKE profile view)

Use match local address to specify a local interface or IP address to which an IKE profile can be applied.
Use undo match local address to restore the default.
Syntax
match local address { interface-type interface-number | ipv4-address }
undo match local address
Default
An IKE profile can be applied to any local interface or IP address.
Views
IKE profile view
Predefined user roles
network-admin
Parameters
interface-type interface-number: Specifies a local interface. It can be any Layer 3 interface.
ipv4-address: Specifies the IPv4 address of a local interface.
Usage guidelines
Use this command to specify which address or interface can use the IKE profile for IKE negotiation.
Specify the local address configured in IPsec policy view (using the local-address command) for this
command. If no local address is configured, specify the IP address of the interface that references the
IPsec policy.
An IKE profile configured earlier has a higher priority. To give an IKE profile that is configured later a
higher priority, you can configure this command for the profile. For example, suppose you configured IKE
profile A before configuring IKE profile B, and you configured the match remote identity address range
2.2.2.1 2.2.2.100 command for IKE profile A and the match remote identity address range 2.2.2.1
169

Advertisement

Table of Contents
loading

Table of Contents