309
•
The IPsec policies at the two tunnel ends must have IPsec transform sets that use the same
security protocols, security algorithms, and encapsulation mode.
•
The IPsec policies at the two tunnel ends must have the same IKE profile parameters.
•
An IKE-based IPsec policy can use a maximum of six IPsec transform sets. During an IKE
negotiation, IKE searches for a fully matched IPsec transform set at the two ends of the IPsec
tunnel. If no match is found, no SA can be set up, and the packets expecting to be protected will
be dropped.
•
The remote IP address of the IPsec tunnel is required on an IKE negotiation initiator and is
optional on the responder. The remote IP address specified on the local end must be the same
as the local IP address specified on the remote end.
•
The IPsec SA uses the local lifetime settings or those proposed by the peer, whichever are
smaller.
•
The IPsec SA can have both a time-based lifetime and a traffic-based lifetime. The IPsec SA
expires when either lifetime expires.
Directly configuring an IKE-based IPsec policy
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Create an IKE-based IPsec
policy entry and enter its
view.
ipsec
{
ipv6-policy
|
policy
}
policy-name
seq-number
isakmp
By default, no IPsec policies exist.
3.
(Optional.) Configure a
description for the IPsec
policy.
description text
By default, no description is
configured.
4.
Specify an ACL for the IPsec
policy.
security acl
[
ipv6
] {
acl-number
|
name acl-name
} [
aggregation
|
per-host
]
By default, no ACL is specified for
an IPsec policy.
You can specify only one ACL for
an IPsec policy.
5.
Specify IPsec transform sets
for the IPsec policy.
transform-set
transform-set-name
&<1-6>
By default, no IPsec transform
sets are specified for an IPsec
policy.
6.
Specify an IKE profile for the
IPsec policy.
ike-profile
profile-name
By default, no IKE profile is
specified for an IPsec policy.
You can specify only one IKE
profile for an IPsec policy.
For more information about IKE
profiles, see "
."
7.
Specify an IKEv2 profile for
the IPsec policy.
ikev2-profile
profile-name
By default, no IKEv2 profile is
specified for the IPsec policy.
You can specify only one IKEv2
profile for an IPsec policy.
For more information about IKEv2
profiles, see "
8.
Specify the local IP address
of the IPsec tunnel.
local-address
{
ipv4-address
|
ipv6
i
pv6-address
}
By default, the local IPv4 address
of IPsec tunnel is the primary IPv4
address of the interface to which
the IPsec policy is applied, and
the local IPv6 address of the
IPsec tunnel is the first IPv6
address of the interface to which
the IPsec policy is applied.
The local IP address specified by
this command must be the same
Summary of Contents for FlexFabric 5940 SERIES
Page 251: ...238 ...