ipsec profile
profile-name
An IPSec profile is created and the IPSec profile view is displayed.
IPSec profiles can only be applied to IPSec tunnel interfaces.
Step 3
Run:
proposal
proposal-name
An IPSec proposal referenced by an IPSec profile is configured.
An IPSec profile can reference a maximum of 12 IPSec proposals. By default, an IPSec profile
does not reference any IPSec proposals.
NOTE
For details on how to configure an IKE proposal, see
5.4.5 Configuring an IPSec Proposal
Step 4
Run:
ike-peer
peer-name
An IKE peer referenced by an IPSec profile is configured.
By default, an IPSec profile does not reference any IKE peers.
NOTE
For details on how to configure an IKE peer, see
Step 5
(Optional) Run:
pfs
{
dh-group1
|
dh-group2
|
dh-group5
|
dh-group14
}
The Diffie-Hellman group referenced by an IPSec profile during negotiation is configured.
By default, an IPSec profile does not reference any Diffie-Hellman group during negotiation.
Step 6
(Optional) Run:
sa duration
{
traffic-based
kilobytes
|
time-based
seconds
}
The SA lifetime is set.
Step 7
Run:
quit
Return to the system view.
Step 8
(Optional) Run:
ipsec sa global-duration
{
time-based
seconds
|
traffic-based
kilobytes
}
The global SA lifetime is set.
By default, the global SA lifetime represented by time is 3600 seconds; the global SA lifetime
represented by traffic volume is 1843200 kilobytes.
----End
5.5.3 Configuring an IPSec Tunnel Interface
This section describes how to apply an IPSec profile to an IPSec tunnel interface.
Huawei AR1200 Series Enterprise Routers
Configuration Guide - VPN
5 IPSec Configuration
Issue 01 (2012-04-20)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
304