© Copyright IBM Corp. 2011
Chapter 17. IPsec with IPv6
209
Note:
When configuring a manual policy ESP, the ESP authenticator key is
optional.
3. After you configure the IPSec policy, you need to apply it to the interface to
enforce the security policies on that interface and save it to keep it in place after
a reboot. To accomplish this, enter:
Using a Dynamic Key Policy
When you use a dynamic key policy, the first packet triggers IKE and sets the IPsec
SA and IKEv2 SA. The initial packet negotiation also determines the lifetime of the
algorithm, or how long it stays in effect. When the key expires, a new key is
automatically created. This helps prevent break-ins.
To configure a dynamic key policy:
1. Choose a dynamic policy to configure.
2. Configure the policy.
where the following parameters are used:
–
peer’s IPv6 address
The IPv6 address of the peer (for example,
3000::1)
–
index of traffic-selector
A number from1-10
–
index of transform-set
A number from1-10
–
SA lifetime, in seconds
The length of time the SA is to remain in effect; an
integer from120-86400
–
pfs enable
|
disable
Whether to enable or disable the perfect forward
security feature. The default is
disable
.
Note:
In a dynamic policy, the AH and ESP keys are created by IKEv2.
3. After you configure the IPSec policy, you need to apply it to the interface to
enforce the security policies on that interface and save it to keep it in place after
a reboot. To accomplish this, enter:
RS G8000(config-ip)#
interface ip
<IP interface number, 1-128>
RS G8000(config-ip-if)#
address
<IPv6 address>
RS G8000(config-ip-if)#
ipsec manual-policy
<policy index, 1-10>
RS G8000(config-ip-if)#
enable
(enable the IP interface)
RS G8000#
write
(save the current configuration)
RS G8000(config)#
ipsec dynamic-policy
<policy number>
RS G8000(config-ipsec-dynamic)#
peer
<peer’s IPv6 address>
RS G8000(config-ipsec-dynamic)#
traffic-selector
<index of traffic selector>
RS G8000(config-ipsec-dynamic)#
transform-set
<index of transform set>
RS G8000(config-ipsec-dynamic)#
sa-lifetime
<SA lifetime, in seconds>
RS G8000(config-ipsec-dynamic)#
pfs enable
|
disable
RS G8000(config-ip)#
interface ip
<IP interface number, 1-128>
RS G8000(config-ip-if)#
address
<IPv6 address>
RS G8000(config-ip-if)#
ipsec dynamic-policy
<policy index, 1-10>
RS G8000(config-ip-if)#
enable
(enable the IP interface)
RS G8000#
write
(save the current configuration)
Summary of Contents for RackSwitch G8000
Page 1: ...RackSwitch G8000 Application Guide...
Page 2: ......
Page 3: ...RackSwitch G8000 Application Guide...
Page 16: ...16 RackSwitch G8000 Application Guide...
Page 22: ...20 RackSwitch G8000 Application Guide...
Page 23: ...Copyright IBM Corp 2011 21 Part 1 Getting Started...
Page 24: ...22 RackSwitch G8000 Application Guide...
Page 54: ...52 RackSwitch G8000 Application Guide...
Page 55: ...Copyright IBM Corp 2011 53 Part 2 Securing the Switch...
Page 56: ...54 RackSwitch G8000 Application Guide...
Page 92: ...90 RackSwitch G8000 Application Guide...
Page 94: ...92 RackSwitch G8000 Application Guide...
Page 144: ...142 RackSwitch G8000 Application Guide...
Page 145: ...Copyright IBM Corp 2011 143 Part 4 Advanced Switch ing Features...
Page 146: ...144 RackSwitch G8000 Application Guide...
Page 148: ...146 RackSwitch G8000 Application Guide...
Page 182: ...180 RackSwitch G8000 Application Guide...
Page 184: ...182 RackSwitch G8000 Application Guide...
Page 212: ...210 RackSwitch G8000 Application Guide...
Page 258: ...256 RackSwitch G8000 Application Guide...
Page 286: ...284 RackSwitch G8000 Application Guide...
Page 294: ...292 RackSwitch G8000 Application Guide...
Page 298: ...296 RackSwitch G8000 Application Guide...
Page 310: ...308 RackSwitch G8000 Application Guide...
Page 311: ...Copyright IBM Corp 2011 309 Part 7 Network Management...
Page 312: ...310 RackSwitch G8000 Application Guide...
Page 320: ...318 RackSwitch G8000 Application Guide...
Page 332: ...330 RackSwitch G8000 Application Guide...
Page 334: ...332 RackSwitch G8000 Application Guide...
Page 345: ...Copyright IBM Corp 2011 343 Part 9 Appendices...
Page 346: ...344 RackSwitch G8000 Application Guide...
Page 357: ...Copyright IBM Corp 2011 Appendix C Notices 355 Taiwan Class A compliance statement...