
Creating Policies
92
ETEP CLI User Guide
Deploying Management Policies
The
deploy-policy-set
command makes the pending management port policies active on the ETEP. It
restarts the IKE server and updates the policy databases (SAD and SPD). Restarting the IKE server tears
down existing IKE connections and updates the keys. Traffic is dropped until the new Phase 1 SAs are
established.
Prior to deploying policies, we recommend that you review the pending policies to make sure they are
configured correctly. Pay particular attention to policy priorities, selectors, and IKE peer addresses. Use
the
show-policy-set
command to view the active and pending policies
If you find that the deployed policies are not executing as expected, you can restore the backup policies
to revert to the previously executing set of policies.
Deployed policies persist through a power cycle. Clear and discard policies take effect immediately upon
boot up. IKE encrypt policies begin negotiating to establish SAs when policies are deployed to each peer.
Manual key policies should take effect upon boot up. If a manual key policy is not automatically re-
established after a power cycle, initiate a new connection from the IPsec client.
To deploy management port policies to the ETEP:
1 From the
ipsec-config>
prompt, type
deploy-policy-set
and press ENTER.
Related topics:
●
“Viewing the Policy Set” on page 91
●
“Backing Up the Policy Set” on page 91
Managing Policies
This section describes how to manage the policies on the ETEP. Tasks include:
●
“Modifying a Policy” on page 92
●
“Deleting a Policy” on page 93
●
“Restoring the Policy Set” on page 94
Modifying a Policy
You can modify a policy by entering policy-config mode using the name of the policy that you want to
change, and issuing the relevant commands with new settings.
As always, it’s a good idea to make a backup copy of the active policies prior to making any changes. It’s
also good practice to issue the
show-policy-set
command to review the pending changes prior to
deployment.
Related topics:
●
“Viewing the Policy Set” on page 91
●
“Backing Up the Policy Set” on page 91
●
Содержание ET0010A
Страница 7: ...8 ETEP CLI User Guide Contents...
Страница 15: ...Getting Started 16 ETEP CLI User Guide...
Страница 33: ...User Administration 34 ETEP CLI User Guide...
Страница 55: ...Configuring the ETEP 56 ETEP CLI User Guide...
Страница 97: ...Creating Policies 98 ETEP CLI User Guide...
Страница 101: ...Maintenance 102 ETEP CLI User Guide...
Страница 119: ...Troubleshooting 120 ETEP CLI User Guide...
Страница 123: ...FIPS 140 2 Level 2 Operation 124 ETEP CLI User Guide...
Страница 205: ...Command Reference 206 ETEP CLI User Guide...
Страница 211: ...Index 212 ETEP CLI User Guide...