
345
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Configure global IKEv2
DPD.
ikev2 dpd interval
interval
[
retry
seconds
] {
on-demand
|
periodic
}
By default, global DPD is
disabled.
Configuring the IKEv2 NAT keepalive feature
Configure this feature on the IKEv2 gateway behind the NAT device. The gateway then sends NAT
keepalive packets regularly to its peer to keep the NAT session alive, so that the peer can access the
device.
The NAT keepalive interval must be shorter than the NAT session lifetime.
This feature takes effect after the device detects the NAT device.
To configure the IKEv2 NAT keepalive feature:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Set the IKEv2 NAT keepalive
interval.
ikev2 nat-keepalive
seconds
By default, the IKEv2 NAT
keepalive interval is 10 seconds.
Configuring IKEv2 address pools
To perform centralized management on remote users, an IPsec gateway can use an address pool to
assign private IP addresses to remote users.
You must use an IKEv2 address pool together with AAA authorization by specifying the IKEv2
address pool as an AAA authorization attribute. For more information about AAA authorization, see
"
."
To configure IKEv2 address pools:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Configure an IKEv2 IPv4
address pool.
ikev2 address-group
group-name
start-ipv4-address
end-ipv4-address
[
mask
|
mask-length
]
By default, no IKEv2 IPv4 address
pool exists.
3.
Configure an IKEv2 IPv6
address pool.
ikev2 ipv6-address-group
group-name
prefix
prefix/prefix-len
assign-len
assign-len
By default, no IKEv2 IPv6 address
pool exists.
Displaying and maintaining IKEv2
Execute
display
commands in any view and
reset
commands in user view.
Task Command
Display the IKEv2 proposal configuration.
display ikev2 proposal
[
name
|
default
]
Содержание 10500 series
Страница 326: ...312 No duration limit for this SA ...