Download Print this page

Client-Authentication - HP FlexNetwork MSR Series Command Reference Manual

Comware 7 security
Hide thumbs Also See for FlexNetwork MSR Series:

Advertisement

client-authentication

Use client-authentication to enable client authentication.
Use undo client-authentication to disable client authentication.
Syntax
client-authentication xauth
undo client-authentication
Default
Client authentication is disabled.
Views
IKE profile view
Predefined user roles
network-admin
Parameters
xauth: Uses Extended Authentication within ISAKMP/Oakley (XAUTH) for authentication.
Usage guidelines
The client authentication feature provides additional authentication in IKE negotiation for secure
remote access to an IPsec VPN.
When networking an IPsec VPN for remote access, enable client authentication on the IPsec
gateway. During the IKE negotiation, the IPsec gateway uses a RADIUS server to authenticate the
remote users. Remote users who provide the correct username and password pass the
authentication and continue with the negotiation. This feature simplifies the configuration on the
IPsec gateway and ensures the validity of the remote users. If you do not use this feature, you must
configure an IPsec policy and an authentication password for each remote user, which is
time-consuming and difficult to maintain.
Examples
# Enable XAUTH client authentication.
<Sysname> system-view
[Sysname] ike profile test
[Sysname-ike-profile-test] client-authentication xauth
Related commands
local-user
description
Use description to configure a description for an IKE proposal.
Use undo description to restore the default.
Syntax
description text
undo description
Default
An IKE proposal does not have a description.
521

Advertisement

loading