H3C S6550X-HI Series Command Reference Manual page 2322

Table of Contents

Advertisement

user-fqdn user-fqdn-name
argument is a case-sensitive string of 1 to 255 characters, such as adc@test.com. If you do not
specify this argument, the device name configured by using the
user FQDN.
Usage guidelines
For digital signature authentication, the device can use any type of ID. For preshared key
authentication, the device can use any type of ID other than the DN.
In digital signature authentication, if the local ID is an IP address that is different from the IP address
in the local certificate, the device uses its FQDN instead. The FQDN is the device name configured
by using the
In aggressive mode, for digital signature authentication, if the local ID is the DN in the local certificate,
the device uses its FQDN instead for IKE negotiation. To use the DN in the local certificate as the
local ID for IKE negotiation, execute the
command in system view.
The initiator uses the local ID to identify itself to the responder. The responder compares the
initiator's ID with the peer IDs configured by the
IKE profile.
An IKE profile can have only one local ID.
An IKE profile with no local ID specified uses the local ID configured by using the
command in system view.
Examples
# Set the local ID to IP address 2.2.2.2.
<Sysname> system-view
[Sysname] ike profile prof1
[Sysname-ike-profile-prof1] local-identity address 2.2.2.2
Related commands
match remote
ike identity
ike signature-identity from-certificate
match local address (IKE keychain view)
Use
match local address
can be applied.
Use
undo match local address
Syntax
match local address { interface-type interface-number | { ipv4-address |
ipv6 ipv6-address } [ vpn-instance vpn-instance-name ] }
undo match local address
Default
An IKE keychain can be applied to any local interface or IP address.
Views
IKE keychain view
: Uses a user FQDN as the local ID. The
command.
sysname
to specify a local interface or IP address to which an IKE keychain
ike signature-identity from-certificate
match remote
to restore the default.
28
user-fqdn-name
command is used as the
sysname
command to look for a matching
ike identity

Advertisement

Table of Contents
loading

Table of Contents