© Copyright Lenovo 2017
Chapter 25: Using IPsec with IPv6
425
2.
Decide
whether
to
use
tunnel
or
transport
mode.
The
default
mode
is
transport.
3.
To
describe
the
packets
to
which
this
policy
applies,
create
a
traffic
selector
using
the
following
commands:
where
the
following
parameters
are
used:
traffic
selector
number
an
integer
from
1
‐
10
permit|deny
whether
or
not
to
permit
IPsec
encryption
of
traffic
that
meets
the
criteria
specified
in
this
command
proto/any
apply
the
selector
to
any
type
of
traffic
proto/icmp
type
|any
only
apply
the
selector
only
to
ICMP
traffic
of
the
specified
type
(an
integer
from
1
‐
255)
or
to
any
ICMP
traffic
proto/tcp
only
apply
the
selector
to
TCP
traffic
source
IP
address
|any
the
source
IP
address
in
IPv6
format
or
“any”
source
destination
IP
address
|any
the
destination
IP
address
in
IPv6
format
or
“any”
destination
prefix
length
(Optional)
the
length
of
the
destination
IPv6
prefix;
an
integer
from
1
‐
128
Permitted
traffic
that
matches
the
policy
in
force
is
encrypted,
while
denied
traffic
that
matches
the
policy
in
force
is
dropped.
Traffic
that
does
not
match
the
policy
bypasses
IPsec
and
passes
through
clear
(unencrypted).
4.
Choose
whether
to
use
a
manual
or
a
dynamic
policy.
CN 4093(config)#
ipsec transform-set tunnel
|
transport
CN 4093(config)#
ipsec traffic-selector
<traffic
selector
number>
{permit|deny}
{any|icmp {
<ICMPv6
type>
|any}|tcp}
{
<source
IP
address>
|
any}
{
<destination
IP
address>
|
|any}
[
<prefix
length>
]
Summary of Contents for Flex System Fabric CN4093
Page 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Page 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Page 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Page 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Page 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Page 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Page 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Page 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Page 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Page 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Page 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Page 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Page 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Page 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Page 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Page 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Page 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Page 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Page 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Page 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Page 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Page 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Page 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Page 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Page 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Page 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Page 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Page 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Page 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Page 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Page 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Page 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Page 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Page 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Page 633: ......
Page 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...