Configuring An Ipsec Proposal - Huawei S9700 Series Configuration Manual

Terabit routing switches spu
Hide thumbs Also See for S9700 Series:
Table of Contents

Advertisement

S9700 Core Routing Switch
Configuration Guide - SPU
If pre-shared key authentication is configured, configure a pre-shared key for each remote peer.
The two ends of an IPSec tunnel must use the same pre-shared key.
When pre-shared key authentication is configured, an authenticator must be configured.
Step 10 (Optional) Run:
remote-address [ vpn-instance vpn-instance-name ][ vpn-instance vpn-instance-
name ] ip-address
The IP address or the domain name of the remote peer is configured.
Step 11 (Optional) Run:
sa binding vpn-instance vpn-instance-name
A VPN instance is associated with the SA.
By specifying the VPN instance that the remote end of the IPSec tunnel belongs to, you can
implement multi-instance IPSec connections. The configuration takes effect only on the initiator
of the IPSec tunnel. The initiator needs to obtain the outbound interface when sending packets.
This command specifies the VPN that the remote end belongs to. According to the VPN, the
tunnel initiator can obtain the outbound interface and send packets through the outbound
interface. The packets received by the remote peer contain the VPN attribute, so you do not need
to specify the VPN on the remote peer.
Step 12 (Optional) Run:
remote-name name
The remote host name is configured. Perform this step only when name authentication is used
in aggressive mode.
If IKEv2 is used, set local-id-type to ip and peer-id-type to name, and configure remote-
name.
Step 13 Run:
quit
Return to the system view.
Step 14 (Optional) Run:
ike local-name local-name
The local host name used in the IKE negotiation is configured.
Perform this step when the local-id-type is set to name.
----End

4.4.5 Configuring an IPSec Proposal

Both ends of the tunnel must be configured with the same security protocol, authentication
algorithm, encryption algorithm, and packet encapsulation mode.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Issue 01 (2012-03-15)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
4 IPSec Configuration
124

Advertisement

Table of Contents
loading

Table of Contents