H3C S6550X-HI Series Command Reference Manual page 2359

Table of Contents

Advertisement

Usage guidelines
This command takes effect when the device resides in the private network behind a NAT device. The
device must send NAT keepalive packets regularly to its peer to keep the NAT session alive, so that
the peer can access the device.
The NAT keepalive interval must be shorter than the NAT session lifetime.
Examples
# Set the NAT keepalive interval to 5 seconds.
<Sysname> system-view
[Sysname] ikev2 nat-keepalive 5
ikev2 policy
Use
ikev2 policy
IKEv2 policy.
Use
undo ikev2 policy
Syntax
ikev2 policy policy-name
undo ikev2 policy policy-name
Default
An IKEv2 policy named
local addresses.
Views
System view
Predefined user roles
network-admin
Parameters
policy-name
of 1 to 63 characters.
Usage guidelines
Each end must have an IKEv2 policy for the IKE_SA_INIT exchange. The initiator looks up an IKEv2
policy by the IP address of the interface to which the IPsec policy is applied and the VPN instance to
which the interface belongs. The responder looks up an IKEv2 policy by the IP address of the
interface that receives the IKEv2 packet and the VPN instance to which the interface belongs. An
IKEv2 policy uses IKEv2 proposals to define the encryption algorithms, integrity protection
algorithms, PRF algorithms, and DH groups to be used for negotiation.
You can configure multiple IKEv2 policies. An IKEv2 policy must have a minimum of one IKEv2
proposal. Otherwise, the policy is incomplete.
If the initiator uses an IPsec policy that is bound to a source interface, the initiator looks up an IKEv2
policy by the IP address of the source interface.
You can set priorities to adjust the match order of IKEv2 policies that have the same match criteria.
If no IKEv2 policy is configured, the default IKEv2 policy is used. You cannot enter the view of the
default IKEv2 policy, nor modify it.
Examples
# Create an IKEv2 policy named policy1 and enter IKEv2 policy view.
to create an IKEv2 policy and enter its view, or enter the view of an existing
to delete an IKEv2 policy.
exists, which uses the default IKEv2 proposal and matches any
default
: Specifies a name for the IKEv2 policy. The policy name is a case-insensitive string
25

Advertisement

Table of Contents
loading

Table of Contents