Applying Ipsec Policy Group To Interface; Other Ipsec Configurations - H3C SecPath F1800-A Operation Manual

H3c secpath f1800-a firewall
Hide thumbs Also See for H3C SecPath F1800-A:
Table of Contents

Advertisement

Operation Manual - VPN
H3C SecPath F1800-A Firewall

3.2.4 Applying IPSec Policy Group to Interface

This configuration task is to apply an IPSec policy group to an interface so as to
protect various data streams passing the interface. If the applied IPSec policy is to
create an SA in manual mode, an SA will be generated instantly. If the applied IPSec
policy is to create an SA in IKE negotiation mode, an SA will be created only when IKE
is enabled. Namely, when some data stream that matches a certain IPSec policy is
sent over the interface.
Do as follows in interface view.
Table 3-15 Applying IPSec policy group
Apply the IPSec policy group.
Remove the IPSec policy group in use.
An interface can only use one IPSec policy group, and one IPSec policy group can be
used on several interfaces. However, the IPSec policy in manual mode can be used
on one interface only.
When a packet is sent from an interface, each IPSec policy in the IPSec policy group
will be searched based on sequence numbers in ascending order. If an ACL quoted
by the IPSec policy matches the packet, the packet will be processed by this IPSec
policy. If the packet is not matched, keep on searching the next IPSec policy. If the
packet can not match any ACL quoted by the IPSec policy, it will be directly sent
(IPSec does not protect the packet).
IPSec policies fulfilled by the SecPath F1800-A can apply on physical interfaces such
as serial ports and Ethernet ports, as well as on virtual interfaces such as Tunnel and
Virtual Template. In this way, IPSec can be applied on tunnels like GRE and L2TP
based on the networking requirements.
Using the undo ipsec policy command, you can remove the IPSec policy group in
use on the interface. Since then, this interface will support IPSec protection no longer.

3.2.5 Other IPSec Configurations

I. Configuring Global Life Duration of SA
The global life duration of SA can be modified. All SAs that are not configured with
separate life durations in IPSec policy view apply the global life duration. When
negotiating an SA for IPSec, IKE will apply the shorter one between the local life
duration and the peer life duration.
There are two types of life duration:
Time-based life duration
Action
7-56
Chapter 3 IPSec Configuration
Command
ipsec policy policy-name
undo ipsec policy

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the H3C SecPath F1800-A and is the answer not in the manual?

Subscribe to Our Youtube Channel

Table of Contents