Ipsec Redundancy Enable - H3C MSR Series Command Reference Manual

Comware 7 security
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

Syntax
ipsec profile profile-name [ manual | isakmp ]
undo ipsec profile profile-name
Default
No IPsec profiles exist.
Views
System view
Predefined user roles
network-admin
Parameters
profile-name: Specifies a name for the IPsec profile, a case-insensitive string of 1 to 63 characters.
manual: Specifies the IPsec SA setup mode as manual.
isakmp: Specifies the IPsec SA setup mode as IKE.
Usage guidelines
When you create an IPsec profile, you must specify the IPsec SA setup mode (isakmp or manual).
When you enter the view of an existing IPsec profile, you do not need to specify the IPsec SA setup
mode.
A manual IPsec profile is similar to a manual IPsec policy. It is used exclusively for IPsec protection
for application protocols, including OSPFv3, IPv6 BGP, and RIPng.
An IKE-based IPsec profile is similar to an IKE-based IPsec policy. It uses IKE negotiation to
establish IPsec SAs to protect both IPv4 and IPv6 application protocols, such as ADVPN. An
IKE-based IPsec profile does not require you to specify the remote end address or an ACL.
Examples
# Create a manual IPsec profile named profile1.
<Sysname> system-view
[Sysname] ipsec profile profile1 manual
[Sysname-ipsec-profile-manual-profile1]
# Create an IKE-based IPsec profile named profile1.
<Sysname> system-view
[Sysname] ipsec profile profile1 isakmp
[Sysname-ipsec-profile-isakmp-profile1]
Related commands
display ipsec profile

ipsec redundancy enable

Use ipsec redundancy enable to enable IPsec redundancy.
Use undo ipsec redundancy enable to disable IPsec redundancy.
Syntax
ipsec redundancy enable
undo ipsec redundancy enable
547

Advertisement

Table of Contents
loading

Table of Contents