348
NE2552E Application Guide for ENOS 8.4
Using a Manual Key Policy
A
manual
policy
involves
configuring
policy
and
manual
SA
entries
for
local
and
remote
peers.
To
configure
a
manual
key
policy,
you
need:
The
IP
address
of
the
peer
in
IPv6
format
(for
example,
“3000::1”).
Inbound/Outbound
session
keys
for
the
security
protocols.
You
can
then
assign
the
policy
to
an
interface.
The
peer
represents
the
other
end
of
the
security
association.
The
security
protocol
for
the
session
key
can
be
either
ESP
or
AH.
To
create
and
configure
a
manual
policy:
1.
Enter
a
manual
policy
to
configure.
2.
Configure
the
policy.
where
the
following
parameters
are
used:
peer’s
IPv6
address
The
IPv6
address
of
the
peer
(for
example,
3000::1)
IPsec
traffic
‐
selector
A
number
from1
‐
10
IPsec
of
transform
‐
set
A
number
from1
‐
10
inbound
AH
IPsec
key
The
inbound
AH
key
code,
in
hexadecimal
inbound
AH
IPsec
SPI
A
number
from
256
‐
4294967295
inbound
ESP
cipher
key
The
inbound
ESP
key
code,
in
hexadecimal
inbound
ESP
SPI
A
number
from
256
‐
4294967295
inbound
ESP
authenticator
key
The
inbound
ESP
authenticator
key
code,
in
hexadecimal
outbound
AH
IPsec
key
The
outbound
AH
key
code,
in
hexadecimal
outbound
AH
IPsec
SPI
A
number
from
256
‐
4294967295
outbound
ESP
cipher
key
The
outbound
ESP
key
code,
in
hexadecimal
outbound
ESP
SPI
A
number
from
256
‐
4294967295
NE2552E(config)#
ipsec manual-policy
<policy
number>
NE2552E(config-ipsec-manual)#
peer
<peer’s
IPv6
address>
NE2552E(config-ipsec-manual)#
traffic-selector
<IPsec
traffic
selector>
NE2552E(config-ipsec-manual)#
transform-set
<IPsec
transform
set>
NE2552E(config-ipsec-manual)#
in-ah auth-key
<inbound
AH
IPsec
key>
NE2552E(config-ipsec-manual)#
in-ah auth-spi
<inbound
AH
IPsec
SPI>
NE2552E(config-ipsec-manual)#
in-esp cipher-key
<inbound
ESP
cipher
key>
NE2552E(config-ipsec-manual)#
in-esp auth-spi
<inbound
ESP
SPI>
NE2552E(config-ipsec-manual)#
in-esp auth-key
<inbound
ESP
authenticator
key>
NE2552E(config-ipsec-manual)#
out-ah auth-key
<outbound
AH
IPsec
key>
NE2552E(config-ipsec-manual)#
out-ah auth-spi
<outbound
AH
IPsec
SPI>
NE2552E(config-ipsec-manual)#
out-esp cipher-key
<outbound
ESP
cipher
key>
NE2552E(config-ipsec-manual)#
out-esp auth-spi
<outbound
ESP
SPI>
NE2552E(config-ipsec-manual)#
out-esp auth-key
<outbound
ESP
authenticator
key>
Summary of Contents for ThinkSystem NE2552E
Page 27: ... Copyright Lenovo 2018 27 Part 1 Getting Started ...
Page 28: ...28 NE2552E Application Guide for ENOS 8 4 ...
Page 70: ...70 NE2552E Application Guide for ENOS 8 4 ...
Page 85: ... Copyright Lenovo 2018 85 Part 2 Securing the Switch ...
Page 86: ...86 NE2552E Application Guide for ENOS 8 4 ...
Page 112: ...112 NE2552E Application Guide for ENOS 8 4 ...
Page 134: ...134 NE2552E Application Guide for ENOS 8 4 ...
Page 154: ...154 NE2552E Application Guide for ENOS 8 4 ...
Page 194: ...194 NE2552E Application Guide for ENOS 8 4 ...
Page 218: ...218 NE2552E Application Guide for ENOS 8 4 ...
Page 234: ...234 NE2552E Application Guide for ENOS 8 4 ...
Page 238: ...238 NE2552E Application Guide for ENOS 8 4 ...
Page 239: ... Copyright Lenovo 2018 239 Part 4 Advanced Switching Features ...
Page 240: ...240 NE2552E Application Guide for ENOS 8 4 ...
Page 242: ...242 NE2552E Application Guide for ENOS 8 4 ...
Page 278: ...278 NE2552E Application Guide for ENOS 8 4 ...
Page 284: ...284 NE2552E Application Guide for ENOS 8 4 ...
Page 314: ...314 NE2552E Application Guide for ENOS 8 4 ...
Page 338: ...338 NE2552E Application Guide for ENOS 8 4 ...
Page 374: ...374 NE2552E Application Guide for ENOS 8 4 ...
Page 388: ...388 NE2552E Application Guide for ENOS 8 4 ...
Page 418: ...418 NE2552E Application Guide for ENOS 8 4 ...
Page 430: ...430 NE2552E Application Guide for ENOS 8 4 ...
Page 432: ...432 NE2552E Application Guide for ENOS 8 4 ...
Page 436: ...436 NE2552E Application Guide for ENOS 8 4 ...
Page 460: ...460 NE2552E Application Guide for ENOS 8 4 ...
Page 461: ... Copyright Lenovo 2018 461 Part 7 Network Management ...
Page 462: ...462 NE2552E Application Guide for ENOS 8 4 ...
Page 476: ...476 NE2552E Application Guide for ENOS 8 4 ...
Page 498: ...498 NE2552E Application Guide for ENOS 8 4 ...
Page 520: ...520 NE2552E Application Guide for ENOS 8 4 ...
Page 534: ...534 NE2552E Application Guide for ENOS 8 4 ...
Page 536: ...536 NE2552E Application Guide for ENOS 8 4 ...
Page 544: ...544 NE2552E Application Guide for ENOS 8 4 ...
Page 549: ... Copyright Lenovo 2018 549 Part 9 Appendices ...
Page 550: ...550 NE2552E Application Guide for ENOS 8 4 ...
Page 566: ...566 NE2552E Application Guide for ENOS 8 4 ...
Page 572: ...572 NE2552E Application Guide for ENOS 8 4 ...
Page 573: ......
Page 574: ...Part Number 01KN246 Printed in USA IP P N 01KN246 ...