IPsec Dynamic Policy Configuration
594
G8264 Command Reference for ENOS 8.4
The following table describes the commands used to configure an IPsec dynamic
policy.
Table 325.
IPsec Dynamic Policy Options
Command Syntax and Usage
ipsec dynamicpolicy <1‐10>
Enter IPsec dynamic policy mode.
Command mode: Global configuration
peer <IPv6 address>
Sets the remote peer IP address.
Command mode: IPsec dynamic policy
pfs {enable|disable}
Enables or disables perfect forward security.
Command mode: IPsec dynamic policy
salifetime <120‐86400>
Sets the IPsec SA lifetime in seconds.
The default value is 86400 seconds.
Command mode: IPsec dynamic policy
trafficselector <1‐10>
Sets the traffic selector for the IPsec policy.
Command mode: IPsec dynamic policy
transformset <1‐10>
Sets the transform set for the IPsec policy.
Command mode: IPsec dynamic policy
show ipsec dynamicpolicy <1‐10>
Displays the current IPsec dynamic policy settings.
Command mode: All