Configuring An Ike Peer - 3Com MSR 50 Series Configuration Manual

3com msr 30-16: software guide
Hide thumbs Also See for MSR 50 Series:
Table of Contents

Advertisement

Configuring an IKE
Peer
To do...
Specify an authentication
algorithm for the IKE proposal
Specify a DH group for key
negotiation in phase 1
Specify the ISAKMP SA
lifetime for the IKE proposal
n
Before an ISAKMP SA expires, IKE will negotiate a new SA to replace it. Since DH
calculation in the IKE negotiation takes longer time especially on low-end devices,
it is recommended to set the lifetime greater than 10 minutes to prevent the
update from influencing normal communication.
Follow these steps to configure an IKE peer:
To do...
Enter system view
Create an IKE peer and enter
IKE peer view
Specify the IKE negotiation
mode in phase 1
Configure the pre-shared
key for pre-shared key
authentication
Configure the PKI domain
for digital signature
authentication
Select the ID type in IKE
negotiation phase 1
Specify the
Specify a
names of
name for the
two ends
local security
gateway
Specify a
name for the
remote
security
gateway
Specify the
Specify an IP
IP addresses
address for
of two ends
the local
security
gateway
Specify one or
more IP
addresses for
the remote
security
gateway
Use the command...
authentication-algorithm
{ md5 | sha }
dh { group1 | group2 |
group5 | group14 }
sa duration seconds
Use the command...
system-view
ike peer peer-name
exchange-mode
{ aggressive | main }
pre-shared-key key
certificate domain
domain-name
id-type { ip | name }
Refer to
"Configuring a Name
for the Local Security
Gateway" on page 1904
remote-name name
local-address ip-address
remote-address
low-ip-address
[ high-ip-address ]

Configuring an IKE Peer

1905
Remarks
Optional
SHA1 by default
Optional
group1, namely the 768-bit
DH group, by default
Optional
86,400 seconds by default
Remarks
-
Required
Optional
main by default
Required
Configure either command
according to the
authentication method for the
IKE proposal.
Optional
ip by default
Optional
Optional
The master IP address of the
interface referencing the
security policy is used as the
local gateway IP address by
default.

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents