560
Field
Description
Match criteria
Criteria for looking up the IKEv2 profile.
Local identity
ID of the local end.
Local authentication method
Method that the local end uses for authentication.
Remote authentication methods
Methods that the remote end uses for authentication.
Keychain
IKEv2 keychain that the IKEv2 profile uses.
Sign certificate domain
PKI domain used for signature generation.
Verify certificate domain
PKI domain used for verifying the remote end's certificate.
SA duration
Lifetime of the IKEv2 SA.
DPD
DPD settings:
•
Detection interval in seconds.
•
Retry interval in seconds.
•
Detection mode, on demand or periodically.
If DPD is disabled, this field displays
Disabled
.
Config exchange
Configuration exchange settings:
•
request
—The local end sends request messages
carrying the configuration request payload during the
IKE_AUTH exchange.
•
set accept
—The local end accepts the configuration set
payload carried in Info messages.
•
set send
—The local end sends Info messages carrying
the configuration set payload.
NAT keepalive
NAT keepalive interval in seconds.
Inside vrf
Inside VPN instance.
AAA authorization
AAA authorization settings:
•
ISP domain name.
•
Username.
Related commands
ikev2
profile
display ikev2 proposal
Use
display ikev2 proposal
to display the IKEv2 proposal configuration.
Syntax
display ikev2 proposal
[
name
|
default
]
Views
Any view
Predefined user roles
network-admin
network-operator
Parameters
name
: Specifies an IKEv2 proposal by its name, a case-insensitive string of 1 to 63 characters.
Summary of Contents for FlexNetwork MSR Series
Page 1005: ...987 ...