HP 6125XLG Configuration Manual page 235

Blade switch security configuration guide
Table of Contents

Advertisement

Step
3.
Configure a peer ID.
4.
Specify the keychain for
pre-shared key
authentication.
5.
Specify the IKE negotiation
mode for phase 1.
6.
Specify the IKE proposals for
the IKE profile to reference.
7.
Configure the local ID.
8.
(Optional.) Configure IKE
DPD.
9.
(Optional.) Specify a local
interface or IP address that
the IKE profile can be
applied to.
Command
match remote { certificate policy-name
| identity { address { { ipv4-address
[ mask | mask-length ] | range
low-ipv4-address high-ipv4-address } |
ipv6 { ipv6-address [ prefix-length ] |
range low-ipv6-address
high-ipv6-address } } [ vpn-instance
vpn-name ] | fqdn fqdn-name |
user-fqdn user-fqdn-name } }
keychain keychain-name
In non-FIPS mode:
exchange-mode { aggressive |
main }
In -FIPS mode:
exchange-mode main
proposal proposal-number&<1-6>
local-identity { address { ipv4-address
| ipv6 ipv6-address } | dn | fqdn
[ fqdn-name ] | user-fqdn
[ user-fqdn-name ] }
dpd interval interval-seconds [ retry
seconds ] { on-demand | periodic }
match local address { interface-type
interface-number | { ipv4-address |
ipv6 ipv6-address } [ vpn-instance
vpn-name ] }
226
Remarks
By default, an IKE profile has no
peer ID.
Each of the two peers must have
at least one peer ID configured.
Configure either or both of the
commands as required.
By default, no IKE keychain is
specified for an IKE profile.
By default, the main mode is
used during IKE negotiation
phase 1.
By default, an IKE profile
references no IKE proposals
and uses the IKE proposals
configured in system view for
IKE negotiation.
By default, no local ID is
configured for an IKE profile,
and an IKE profile uses the local
ID configured in system view. If
no local ID is configured in
system view either, the IP
address of the interface that the
IPsec policy or IPsec policy
template is applied to is used as
the local ID.
By default, the IKE DPD function
is not configured for an IKE
profile and an IKE profile uses
the DPD settings configured in
system view. If the IKE DPD
function is not configured in
system either, the device does
not perform dead IKE peer
detection.
By default, an IKE profile can be
applied to any local interface or
IP address.

Advertisement

Table of Contents
loading

Table of Contents