3Com MSR 50 Series Configuration Manual page 1885

3com msr 30-16: software guide
Hide thumbs Also See for MSR 50 Series:
Table of Contents

Advertisement

To do...
Enter system view
Create an IPSec policy and
enter its view
Specify the ACL for the
IPSec policy to reference
Specify the IPSec
proposal(s) for the IPSec
policy to reference
Specify the IKE peers for
the IPSec policy to
reference
Enable and configure the
perfect forward secrecy
feature for the IPSec policy
Configure SA lifetime
Return to system view
Configure the global SA
lifetime
Configuring an IKE-dependent IPSec policy by referencing an IPSec policy
template
The parameters configurable for an IPSec policy template are the same as those
you can configure when directly configuring an IKE-dependent IPSec policy. The
difference is that more parameters are optional and only the IPSec proposals and
IKE peer are required.
Follow these steps to configure an IKE-dependent IPSec policy by referencing an
IPSec policy template:
To do...
Enter system view
Create an IPSec policy
template and enter its view
Specify the ACL for the
IPSec policy to reference
Use the command...
system-view
ipsec policy policy-name
seq-number isakmp
security acl acl-number
proposal
proposal-name&<1-6>
ike-peer peer-name
pfs { dh-group1 |
dh-group2 | dh-group5 |
dh-group14 }
sa duration { time-based
seconds | traffic-based
kilobytes }
quit
ipsec sa global-duration
{ time-based seconds |
traffic-based kilobytes }
Use the command...
system-view
ipsec policy-template
template-name seq-number
security acl acl-number
Configuring an IPSec Policy
Remark
-
Required
By default, no IPSec policy exists.
Required
By default, an IPSec policy
references no ACL.
Required
By default, an IPSec policy
references no IPSec proposal.
Required
Optional
By default, the PFS feature is not
used for negotiation.
For information about PFS, refer to
"Security Mechanisms of IKE" on
page
1901.
Optional
3,600 seconds for time-based SA
lifetime by default
1,843,200 kilobytes for
traffic-based SA lifetime by default
-
Optional
3,600 seconds for time-based SA
lifetime by default
1,843,200 kilobytes for
traffic-based SA lifetime by default
Remark
-
Required
By default, no IPSec policy
template exists.
Optional
By default, an IPSec policy
references no ACL.
1885

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents