488
Examples
# Configure the number of the GDOI KS group
abc
as
123456
.
<Sysname> system-view
[Sysname]gdoi ks group abc
[Sysname-gdoi-ks-group-abc] identity number 123456
Related commands
•
identity
address
•
gdoi ks group
ipsec
Use
ipsec
to create an IPsec policy for the GDOI KS group and enter GDOI KS IPsec policy view.
Use
undo ipsec
to delete an IPsec policy for the GDOI KS group.
Syntax
ipsec
sequence-number
undo ipsec
sequence-number
Default
No IPsec policy is created for a GDOI KS group.
Views
GDOI KS group view
Default command level
2: System level
Parameters
sequence-number
: Specifies a sequence number for the IPsec policy, in the range of 1 to 65535.
Usage guidelines
You can create multiple IPsec policies for a GDOI KS group. An IPsec policy with a smaller number
has a higher priority. A KS can send multiple IPsec policies to GMs at a time, and GMs use the IPsec
policies from the one with the highest priority.
Deleting an IPsec policy from a GDOI KS group also deletes the TEK that corresponds to that IPsec
policy.
Examples
# Create IPsec policy 10 for the GDOI KS group
abc
and enter its view.
<Sysname> system-view
[Sysname] gdoi ks group abc
[Sysname-gdoi-ks-group-abc] ipsec 10
[Sysname-gdoi-ks-group-abc-ipsec-10]
Related commands
gdoi ks group
local priority
Use
local priority
to configure the GDOI KS local priority.
Use
undo local priority
to restore the default.