Huawei S9700 Series Configuration Manual page 153

Terabit routing switches spu
Hide thumbs Also See for S9700 Series:
Table of Contents

Advertisement

S9700 Core Routing Switch
Configuration Guide - SPU
[SPU] display ipsec policy
===========================================
IPsec Policy Group: "map1"
Using interface: {}
===========================================
Step 8 Apply the IPSec policies to the interfaces of the SPUs on SwitchA and SwitchB.
# Apply the IPSec policy to the SPU interface on SwitchA.
[SPU] interface XGigabitEthernet 0/0/1.1
[SPU-XGigabitEthernet0/0/1.1] ipsec policy map1
[SPU-XGigabitEthernet0/0/1.1] quit
# Apply the IPSec policy to the SPU interface on SwitchB.
[SPU] interface XGigabitEthernet 0/0/1.1
[SPU-XGigabitEthernet0/0/1.1] ipsec policy use1
[SPU-XGigabitEthernet0/0/1.1] quit
Run the display ipsec sa command on the SPUs of SwitchA and SwitchB to view the
configuration. Take the display on the SPU of SwitchA as an example.
[SPU] display ipsec sa
===============================
Interface: XGigabitEthernet 0/0/1.1
===============================
-----------------------------
IPSec policy name: "map1"
Sequence number: 10
mode: isakmp
-----------------------------
Step 9 Verify the configuration.
After the configuration is complete, PC A can ping PC B. The data transmitted between PC A
and PC B is encrypted.
Run the display ike sa command on an SPU, and the following information is displayed:
[SPU] display ike sa
-----------------------------------------------------------
Issue 01 (2012-03-15)
SequenceNumber: 10
Security data flow: 3101
Peer name:
spub
Perfect forward secrecy: None
Proposal name:
tran1
IPsec SA local duration(time based): 3600 seconds
IPsec SA local duration(traffic based): 1843200 kilobytes
SA trigger mode: Automatic
Path MTU: 1500
Connection id: 3
encapsulation mode: tunnel
tunnel local : 202.38.163.1
[inbound ESP SAs]
spi: 1406123142 (0x53cfbc86)
proposal: ESP-ENCRYPT-DES ESP-AUTH-SHA1
sa remaining key duration (bytes/sec): 1887436528/3575
max received sequence-number: 4
udp encapsulation used for nat traversal: N
[outbound ESP SAs]
spi: 3835455224 (0xe49c66f8)
proposal: ESP-ENCRYPT-DES ESP-AUTH-SHA1
sa remaining key duration (bytes/sec): 1887436464/3575
max sent sequence-number: 5
udp encapsulation used for nat traversal: N
Conn-ID
Peer
14
202.38.162.1
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
tunnel remote: 202.38.162.1
VPN
Flag(s)
Phase
0
RD|ST
4 IPSec Configuration
1
142

Advertisement

Table of Contents
loading

Table of Contents