HPE FlexNetwork 5510 HI Series Security Configuration Manual page 320

Hide thumbs Also See for FlexNetwork 5510 HI Series:
Table of Contents

Advertisement

IKE profile: profile1
SA duration(time based):
SA duration(traffic based):
SA idle time:
2.
Verify that the ACL used by the IPsec policy is correctly configured. If the flow range defined by
the responder's ACL is smaller than that defined by the initiator's ACL, IPsec proposal matching
will fail.
For example, if the initiator's ACL defines a flow from one network segment to another but the
responder's ACL defines a flow from one host to another host, IPsec proposal matching will fail.
# On the initiator:
[Sysname] display acl 3000
Advanced ACL
ACL's step is 5
rule 0 permit ip source 192.168.222.0 0.0.0.255 destination 192.168.222.0 0.0.0.255
# On the responder:
[Sysname] display acl 3000
Advanced ACL
ACL's step is 5
rule 0 permit ip source 192.168.222.71 0 destination 192.168.222.5 0
3.
Verify that the IPsec policy has a remote address and an IPsec transform set configured and
that the IPsec transform set has all necessary settings configured.
If, for example, the IPsec policy has no remote address configured, the IPsec SA negotiation
will fail:
[Sysname] display ipsec policy
-------------------------------------------
IPsec Policy: policy1
Interface: Vlan-interface1
-------------------------------------------
-----------------------------
Sequence number: 1
Mode: isakmp
-----------------------------
Description:
Security data flow: 3000
Selector mode: aggregation
Local address: 192.168.222.5
Remote address:
Transform set:
IKE profile: profile1
SA duration(time based):
SA duration(traffic based):
SA idle time:
Solution
1.
If no matching IKE profiles were found and the IPsec policy has an IKE profile specified, remove
the specified IKE profile from the IPsec policy.
2.
If the flow range defined by the responder's ACL is smaller than that defined by the initiator's
ACL, modify the responder's ACL so the ACL defines a flow range equal to or greater than that
of the initiator's ACL.
3000, named -none-, 2 rules,
3000, named -none-, 2 rules,
transform1
307

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents