Ikev2 Keychain; Ikev2 Nat-Keepalive - H3C MSR Series Command Reference Manual

Comware 7 security
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

Usage guidelines
Different from the IKEv2 IPv4 address pool, the device assigns an IPv6 subnet to a peer from the
IKEv2 IPv6 address pool. The peer can use the assigned IPv6 subnet to assign IPv6 addresses to
other devices.
IKEv2 IPv6 address pools cannot overlap with each other.
Examples
# Configure an IKEv2 IPv6 address pool with the name ipv6group, prefix 1:1::/64, and the assigned
prefix length 80.
<Sysname> system-view
[Sysname] ikev2 ipv6-address-group ipv6group prefix 1:1::/64 assign-len 80
Related commands
ipv6-address-group

ikev2 keychain

Use ikev2 keychain to create an IKEv2 keychain and enter its view, or enter the view of an existing
IKEv2 keychain.
Use undo ikev2 keychain to delete an IKEv2 keychain.
Syntax
ikev2 keychain keychain-name
undo ikev2 keychain keychain-name
Default
No IKEv2 keychains exist.
Views
System view
Predefined user roles
network-admin
Parameters
keychain-name: Specifies a name for the IKEv2 keychain. The keychain name is a case-insensitive
string of 1 to 63 characters and cannot contain a hyphen (-).
Usage guidelines
An IKEv2 keychain is required on both ends if either end uses pre-shared key authentication. The
pre-shared key configured on both ends must be the same.
You can configure multiple IKEv2 peers in an IKEv2 keychain.
Examples
# Create an IKEv2 keychain named key1 and enter IKEv2 keychain view.
<Sysname> system-view
[Sysname] ikev2 keychain key1
[Sysname-ikev2-keychain-key1]

ikev2 nat-keepalive

Use ikev2 nat-keepalive to set the NAT keepalive interval.
633

Advertisement

Table of Contents
loading

Table of Contents