45
Parameters
ipv6
: Specifies the remote address or host name of an IPv6 IPsec tunnel. To specify the remote
address or host name of an IPv4 IPsec tunnel, do not specify this keyword.
hostname
: Specifies the remote host name, a case-insensitive string of 1 to 253 characters. The
host name can be resolved to an IP address by the DNS server.
ipv4-address
: Specifies a remote IPv4 address.
ipv6-address
: Specifies a remote IPv6 address.
Usage guidelines
This remote IP address configuration is required on the IKE negotiation initiator and optional on the
responder if the responder uses an IPsec policy template.
A manual IPsec policy does not support DNS. Therefore, you must specify a remote IP address
rather than a remote host name for the manual IPsec policy.
If you configure a remote host name, make sure the local end can always resolve the host name into
the latest IP address of the remote end.
•
If a DNS server is used for resolution, the local end queries the remote IP address again from
the DNS server after the previously cached remote IP address expires. This mechanism
ensures that the local end can always obtain the latest remote IP address.
•
If a static DNS entry is used for resolution, you must reconfigure the
remote-address
command whenever the remote IP address changes. Without the reconfiguration, the local end
cannot obtain the latest remote IP address.
For example, the local end has a static DNS entry which maps the host name
test
to the IP address
1.1.1.1. Configure the following commands:
# Configure the remote host name to
test
for the IPsec tunnel in the IPsec policy
policy1
.
[Sysname] ipsec policy policy1 1 isakmp
[Sysname-ipsec-policy-isakmp-policy1-1] remote-address test
# Change the IP address for the host
test
to 2.2.2.2.
[Sysname] ip host test 2.2.2.2
In this case, you must reconfigure the remote host name for the IPsec policy
policy1
so that the local
end can obtain the latest IP address of the remote host.
# Reconfigure the remote host name to
test
for the IPsec tunnel in the IPsec policy
policy1
.
[Sysname] ipsec policy policy1 1 isakmp
[Sysname -ipsec-policy-isakmp-policy1-1] remote-address test
Examples
# Specify remote IP address 10.1.1.2 for the IPsec tunnel.
<Sysname> system-view
[Sysname] ipsec policy policy1 10 manual
[Sysname-ipsec-policy-manual-policy1-10] remote-address 10.1.1.2
Related commands
ip host
(
Layer 3—IP Services Command Reference
)
local-address
reset ipsec sa
Use
reset ipsec sa
to clear IPsec SAs.
Summary of Contents for SOHO IE4300
Page 285: ...i Contents Tcl commands 1 cli 1 tclquit 1 tclsh 2...
Page 288: ...i Contents Python commands 1 exit 1 python 1 python filename 2...
Page 291: ...i Contents Automatic configuration commands 1 autodeploy udisk enable 1...
Page 323: ...25 Sysname Ten GigabitEthernet1 0 51 undo shutdown Related commands irf port...
Page 465: ...ii stp vlan enable 55 vlan mapping modulo 55...
Page 602: ...12 Related commands display mvrp statistics...
Page 609: ...i Contents VLAN mapping commands 1 display vlan mapping 1 vlan mapping 2...
Page 678: ...9 Related commands reset pppoe relay statistics...
Page 846: ...i Contents Basic IP forwarding commands 1 display fib 1 ip forwarding table save 2...
Page 1770: ...i Contents Time range commands 1 display time range 1 time range 1...
Page 2026: ...34 Related commands display mac authentication...
Page 2028: ...ii...
Page 2143: ...i Contents User profile commands 1 display user profile 1 user profile 2...
Page 2308: ...61 ipsec transform set...
Page 2531: ...i Contents SAVI commands 1 ipv6 savi down delay 1 ipv6 savi log enable 1 ipv6 savi strict 2...
Page 2534: ...3 Sysname ipv6 savi strict Related commands ipv6 verify source...
Page 2791: ...14 Sysname track 1 Related commands delay display track...
Page 2939: ...9 sntp authentication keyid sntp reliable authentication keyid...
Page 2967: ...27 Related commands apply poe profile poe enable poe max power interface view poe priority...