Inside-Vpn; Keychain - H3C MSR Series Command Reference Manual

Comware 7 security
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

Examples
# Configure the local device to always obtain the identity information from the local certificate for
signature authentication.
<Sysname> system-view
[sysname] ike signature-identity from-certificate
Related commands
local-identity
ike identity

inside-vpn

Use inside-vpn to specify an inside VPN instance.
Use undo inside-vpn to restore the default.
Syntax
inside-vpn vpn-instance vpn-instance-name
undo inside-vpn
Default
No inside VPN instance is specified for an IKE profile. The device forwards protected data to the
VPN instance where the interface that receives the data resides.
Views
IKE profile view
Predefined user roles
network-admin
Parameters
vpn-instance vpn-instance-name: Specifies the MPLS L3VPN instance to which the device
forwards protected data. The vpn-instance-name argument represents the VPN instance name, a
case-sensitive string of 1 to 31 characters.
Usage guidelines
This command determines where the device should forward received IPsec protected data. If you
configure this command, the device looks for a route in the specified VPN to forward the data. If you
do not configure this command, the device looks for a route in the VPN instance where the receiving
interface resides to forward the data.
Examples
# Specify the inside VPN instance vpn1 for IKE profile prof1.
<Sysname> system-view
[Sysname] ike profile prof1
[Sysname-ike-profile-prof1] inside-vpn vpn-instance vpn1

keychain

Use keychain to specify an IKE keychain for pre-shared key authentication.
Use undo keychain to remove an IKE keychain.
Syntax
keychain keychain-name
598

Advertisement

Table of Contents
loading

Table of Contents