269
Step Command
Remarks
6.
Specify an IKE profile for the
IPsec policy.
ike-profile
profile-name
By default, the IPsec policy
references no IKE profile, and the
device selects an IKE profile
configured in system view for
negotiation. If no IKE profile is
configured, the globally
configured IKE settings are used.
An IPsec policy can reference
only one IKE profile, and it cannot
reference any IKE profile that is
already referenced by another
IPsec policy or IPsec policy
template.
For more information about IKE
profiles, see "
."
7.
Specify an IKEv2 profile for
the IPsec policy.
ikev2-profile
profile-name
By default, no IKEv2 profile is
specified for an IPsec policy.
You can specify only one IKEv2
profile for an IPsec policy.
For more information about IKEv2
profiles, see "
8.
Specify the local IP address
of the IPsec tunnel.
local-address
{
ipv4-address
|
ipv6
i
pv6-address
}
By default, the local IPv4 address
of IPsec tunnel is the primary IPv4
address of the interface to which
the IPsec policy is applied, and
the local IPv6 address of the
IPsec tunnel is the first IPv6
address of the interface to which
the IPsec policy is applied.
The local IP address specified by
this command must be the same
as the IP address used as the
local IKE identity.
9.
Specify the remote IP
address of the IPsec tunnel.
remote-address
{ [
ipv6
]
host-name
|
ipv4-address
|
ipv6
ipv6-address
}
By default, the remote IP address
of the IPsec tunnel is not
specified.
10.
Set the IPsec SA lifetime.
sa
duration
{
time-based
seconds
|
traffic-based
kilobytes
}
By default, the global SA lifetime
is used.
11.
(Optional.) Set the IPsec SA
idle timeout.
sa idle-time seconds
By default, the global SA idle
timeout is used.
12.
(Optional.) Enable the Traffic
Flow Confidentiality (TFC)
padding feature.
tfc enable
By default, the TFC padding
feature is disabled.
13.
Return to system view.
quit
N/A
14.
Set the global SA lifetime.
ipsec
sa
global-duration
{
time-based
seconds
|
traffic-based
kilobytes
}
By default, the time-based SA
lifetime is 3600 seconds, and the
traffic-based SA lifetime is
1843200 kilobytes.
15.
(Optional.) Enable the global
IPsec SA idle timeout
feature, and set the global
SA idle timeout.
ipsec sa idle-time seconds
By default, the global IPsec SA
idle timeout feature is disabled.