H3C S6550X-HI Series Command Reference Manual page 2319

Table of Contents

Advertisement

If the initiator is using an IPsec policy with no IKE profile, the initiator sends all its IKE
proposals to the peer. An IKE proposal with a smaller number has a higher priority.
The peer searches its own IKE proposals for a match. The search starts from the IKE proposal
with the highest priority and proceeds in descending order of priority until a match is found. The
matching IKE proposals are used to establish the IKE SA. If all user-defined IKE proposals are
mismatched, the two peers use their default IKE proposals to establish the IKE SA.
Examples
# Create IKE proposal 1 and enter its view.
<Sysname> system-view
[Sysname] ike proposal 1
[Sysname-ike-proposal-1]
Related commands
display ike proposal
ike signature-identity from-certificate
Use
ike signature-identity from-certificate
the identity information from the local certificate for signature authentication.
Use
undo ike signature-identity from-certificate
Syntax
ike signature-identity from-certificate
undo ike signature-identity from-certificate
Default
The local end uses the identity information specified by the
command for signature authentication.
Views
System view
Predefined user roles
network-admin
Usage guidelines
This command requires the local device to always use the identity information in the local certificate
for signature authentication, regardless of the
Configure this command when the aggressive mode and signature authentication are used and the
device interconnects with a Comware 5-based peer device. Comware 5 supports only DN for
signature authentication.
If the
ike signature-identity from-certificate
local-identity
identity
Examples
# Configure the local device to always obtain the identity information from the local certificate for
signature authentication.
<Sysname> system-view
[sysname] ike signature-identity from-certificate
command configuration, if configured, takes precedence over the
command configuration.
to configure the local device to obtain
local-identity
local-identity
command is not configured, the
25
to restore the default.
or
ike identity
or
configuration.
ike identity
ike

Advertisement

Table of Contents
loading

Table of Contents