Brocade Communications Systems NetIron MLXe Series Hardware Installation Manual page 47

Table of Contents

Advertisement

IPsec and IKEv2 configuration
Create a VTI interface by creating a tunnel interface and setting the mode of the tunnel to IPsec IPv4.
To create a tunnel interface and set the mode of the tunnel to IPsec IPv4, perform the following task.
1.
Create a VTI interface by completing the following steps:
a)
Create a VTI interface by entering the interface tunnel x command, where x is the tunnel number.
b)
Set the mode of the tunnel to IPsec IPv4 by entering the tunnel mode ipsec ipv4command.
2.
Configure the following values, if the default values are not acceptable.
IKE Proposal
IKE Policy
IKE Profile
IKE Authentication
IPSEC Proposal
IPSEC Profile
3.
Bind the IPsec Profile to the VTI interface using the tunnel protection ipsec profile profilename command.
Configuring Global IKEv2 Options
Configure global IKEv2 options that are independent of peers. All the global IKE commands start with prefix ikev2.
IKEv2 Option
ikev2 retry-count <number>
ikev2 exchange-max-time
<seconds>
ikev2 retransmit-interval <time>
ikev2 http-url-cert
ikev2 cookie-challenge <number
>
ikev2 limit { max-in-negotiation-
sa limit | max - sa limit }
ikev2 Allow duplicate ike-sa
Brocade NetIron MLXe Series Hardware Installation Guide
53-1004203-04
Description
Maximum number of attempts to retransmit a message. Default 5.
NOTE
Range is 1 to 10.
Maximum setup time for an exchange, in seconds. Default 30 seconds.
NOTE
Range is 0 to 300 seconds.
IKEv2 message resend delay, in seconds. This is the time that the IKEv2 task is to wait before attempting the first
resend of a packet. Default is 5 seconds. Retransmit interval will increase exponentially.
NOTE
Range is 1 to 60 seconds.
Enables the HTTP CERT support. HTTP CERT is disabled by default. If enabled then
HTTP_CERT_LOOKUP_SUPPORTED should be send along with the CERT_REQ payload. Default is disabled.
Enabled an IKEv2 cookie challenge only when the number of half-open IKE SAs crosses the configured number.
Default is disabled.
NOTE
Range is 1 to 2000 (max number of SA supported).
max-in-negotiation-sa limit — Limits the total number of in negotiation IKEv2 SAs on the node. Default is 256.
max-sa limit — Limits the total number of IKEv2 SAs on the LP. Default is 256.
NOTE
For both limits the range is 1 to 256 (max SAs supported).
For a given source/destination and IKE Profile, if multiple IKE SA can be created. This will be applicable only for
incoming IKE session. Default is disabled. This will be used for inter-op with other vendors.
Router modules
47

Advertisement

Table of Contents
loading

Table of Contents