490
Usage guidelines
If you do not specify the
seq-number
argument, the
undo
command deletes the specified IPsec
policy.
An interface applied with an IPsec policy that is configured by using an IPsec policy template cannot
initiate an SA negotiation, but it can respond to a negotiation request. The parameters not defined in
the template are determined by the initiator. When the remote end's information (such as the IP
address) is unknown, this method allows the remote end to initiate negotiations with the local end.
Examples
# Create an IPsec policy entry by using the IPsec policy template
temp1
, and specify the IPsec
policy name as
policy2
and the sequence number as 200.
<Sysname> system-view
[Sysname] ipsec policy policy2 200 isakmp template temp1
Related commands
display ipsec
{
ipv6-policy
|
policy
}
ipsec
{
ipv6-policy-template
|
policy-template
}
ipsec { ipv6-policy | policy } local-address
Use
ipsec
{
ipv6-policy
|
policy
}
local-address
to bind an IPsec policy to a source interface.
Use
undo ipsec
{
ipv6-policy
|
policy
}
local-address
to remove the binding between an IPsec
policy and a source interface.
Syntax
ipsec
{
ipv6-policy
|
policy
}
policy-name local-address interface-type interface-number
undo
ipsec
{
ipv6-policy
|
policy
}
policy-name local-address
Default
No IPsec policy is bound to a source interface.
Views
System view
Predefined user roles
network-admin
Parameters
ipv6-policy
: Specifies an IPv6 IPsec policy.
policy
: Specifies an IPv4 IPsec policy.
policy-name
: Specifies an IPsec policy name, a case-insensitive string of 1 to 63 characters.
local-address interface-type interface-number
: Specifies the shared source interface by its type and
number.
Usage guidelines
For high availability, two interfaces can operate in backup or load sharing mode. After an IPsec policy
is applied to the two interfaces, they negotiate with their peers to establish IPsec SAs separately.
When one interface fails and a link failover occurs, the other interface needs to take some time to
renegotiate SAs, resulting in service interruption.
To solve these problems, bind a source interface to an IPsec policy and apply the policy to both
interfaces. This enables the two physical interfaces to use the same source interface to negotiate