27
isakmp
: Establishes IPsec SAs through IKE negotiation.
manual
: Establishes IPsec SAs manually.
Usage guidelines
When you create an IPsec policy, you must specify the SA setup mode (
isakmp
or
manual
). When
you enter the view of an existing IPsec policy, you do not need to specify the SA setup mode.
You cannot change the SA setup mode of an existing IPsec policy.
An IPsec policy is a set of IPsec policy entries that have the same name but different sequence
numbers. In the same IPsec policy, an IPsec policy entry with a smaller sequence number has a
higher priority.
If you specify the
seq-number
argument, the
undo
command deletes the specified IPsec policy
entry. If you do not specify this argument, the
undo
command deletes the specified IPsec policy.
An IPv4 IPsec policy and IPv6 IPsec policy can have the same name.
Examples
# Create an IKE-based IPsec policy entry and enter the IPsec policy view. The policy name is
policy1
and the sequence number is 100.
<Sysname> system-view
[Sysname] ipsec policy policy1 100 isakmp
[Sysname-ipsec-policy-isakmp-policy1-100]
# Create a manual IPsec policy entry and enter the IPsec policy view. The policy name is
policy1
and the sequence number is 101.
<Sysname> system-view
[Sysname] ipsec policy policy1 101 manual
[Sysname-ipsec-policy-manual-policy1-101]
Related commands
display ipsec
{
ipv6-policy
|
policy
}
ipsec apply
ipsec { ipv6-policy | policy } isakmp template
Use
ipsec
{
ipv6-policy
|
policy
}
isakmp template
to create an IKE-based IPsec
policy entry by using an IPsec policy template.
Use
undo
ipsec
{
ipv6-policy
|
policy
}
to delete an IPsec policy.
Syntax
ipsec
{
ipv6-policy
|
policy
}
policy-name
seq-number
isakmp template
template-name
undo
ipsec
{
ipv6-policy
|
policy
}
policy-name
[
seq-number
]
Default
No IPsec policies exist.
Views
System view
Predefined user roles
network-admin
Summary of Contents for SOHO IE4300
Page 285: ...i Contents Tcl commands 1 cli 1 tclquit 1 tclsh 2...
Page 288: ...i Contents Python commands 1 exit 1 python 1 python filename 2...
Page 291: ...i Contents Automatic configuration commands 1 autodeploy udisk enable 1...
Page 323: ...25 Sysname Ten GigabitEthernet1 0 51 undo shutdown Related commands irf port...
Page 465: ...ii stp vlan enable 55 vlan mapping modulo 55...
Page 602: ...12 Related commands display mvrp statistics...
Page 609: ...i Contents VLAN mapping commands 1 display vlan mapping 1 vlan mapping 2...
Page 678: ...9 Related commands reset pppoe relay statistics...
Page 846: ...i Contents Basic IP forwarding commands 1 display fib 1 ip forwarding table save 2...
Page 1770: ...i Contents Time range commands 1 display time range 1 time range 1...
Page 2026: ...34 Related commands display mac authentication...
Page 2028: ...ii...
Page 2143: ...i Contents User profile commands 1 display user profile 1 user profile 2...
Page 2308: ...61 ipsec transform set...
Page 2531: ...i Contents SAVI commands 1 ipv6 savi down delay 1 ipv6 savi log enable 1 ipv6 savi strict 2...
Page 2534: ...3 Sysname ipv6 savi strict Related commands ipv6 verify source...
Page 2791: ...14 Sysname track 1 Related commands delay display track...
Page 2939: ...9 sntp authentication keyid sntp reliable authentication keyid...
Page 2967: ...27 Related commands apply poe profile poe enable poe max power interface view poe priority...