Ike Nat-Keepalive; Ike Profile - H3C MSR Series Command Reference Manual

Comware 7 security
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

Views
System view
Predefined user roles
network-admin
Usage guidelines
This command enables the device to output logs for the IKE negotiation process.
This command is available only in non-FIPS mode.
Examples
# Enable logging for IKE negotiation.
<Sysname> system-view
[Sysname] ike logging negotiation enable

ike nat-keepalive

Use ike nat-keepalive to set the NAT keepalive interval.
Use undo ike nat-keepalive to restore the default.
Syntax
ike nat-keepalive seconds
undo ike nat-keepalive
Default
The NAT keepalive interval is 20 seconds.
Views
System view
Predefined user roles
network-admin
Parameters
seconds: Specifies the NAT keepalive interval in seconds, in the range of 5 to 300.
Usage guidelines
This command takes effect only for a device that resides in the private network behind a NAT
gateway. The device behind the NAT gateway needs to send NAT keepalives to its peer to keep the
NAT session alive, so that the peer can access the device.
The NAT keepalive interval must be shorter than the NAT session lifetime. For information about how
to display the lifetime of NAT sessions, see Layer 3–IP Services Command Reference.
Examples
# Set the NAT keepalive interval to 5 seconds.
<Sysname> system-view
[Sysname] ike nat-keepalive 5

ike profile

Use ike profile to create an IKE profile and enter its view, or enter the view of an existing IKE profile.
Use undo ike profile to delete an IKE profile.
595

Advertisement

Table of Contents
loading

Table of Contents