H3C S6550X-HI Series Command Reference Manual page 2337

Table of Contents

Advertisement

authentication-method
Use
authentication-method
Use
undo authentication-method
method.
Syntax
authentication-method { local | remote } { dsa-signature | ecdsa-signature |
pre-share | rsa-signature }
undo authentication-method local
undo authentication-method remote { dsa-signature | ecdsa-signature |
pre-share | rsa-signature }
Default
No local or remote identity authentication method is specified.
Views
IKEv2 profile view
Predefined user roles
network-admin
Parameters
: Specifies the local identity authentication method.
local
: Specifies the remote identity authentication method.
remote
dsa-signature
ecdsa-signature
pre-share
rsa-signature
Usage guidelines
The local and remote identity authentication methods must both be specified and they can be
different.
You can specify only one local identity authentication method. You can specify multiple remote
identity authentication methods by executing this command multiple times when there are multiple
remote ends whose authentication methods are unknown.
If you use RSA, DSA, or ECDSA signature authentication, you must specify PKI domains for
obtaining certificates. You can specify PKI domains by using the
in IKEv2 profile view. If you do not specify PKI domains in IKEv2 profile view, the PKI domains
configured by the
If you specify the preshared key method, you must specify a preshared key for the IKEv2 peer in the
keychain used by the IKEv2 profile.
Examples
# Create an IKEv2 profile named profile1.
<Sysname> system-view
[Sysname] ikev2 profile profile1
# Specify the preshared key and RSA signatures as the local and remote authentication methods,
respectively.
: Specifies the DSA signatures as the identity authentication method.
: Specifies the ECDSA signatures as the identity authentication method.
: Specifies the preshared key as the identity authentication method.
: Specifies the RSA signatures as the identity authentication method.
command in system view will be used.
pki domain
to specify the local or remote identity authentication method.
to remove the local or remote identity authentication
3
certificate domain
command

Advertisement

Table of Contents
loading

Table of Contents