
[Huawei]
interface gigabitethernet 0/0/1
[Huawei-GigabitEthernet0/0/1]
ipsec policy routerb
[Huawei-GigabitEthernet0/0/1]
quit
Step 8
Configure devices to request a certificate and download it for IKE negotiation.
# Configure RouterA.
[Huawei]
pki enroll-certificate testa
Create a challenge password. You will need to verbally provide this password to
the CA Administrator in order to revoke your certificate.
For security reasons your password will not be saved in the configuration. Plea
se make a note of it.
Choice no password ,please enter the enter-key.
Please enter Password:
Start certificate enrollment ...
Certificate is enrolling now,It will take a few minutes or more.
Please waiting...
The certificate enroll successful.
# Configure RouterB.
[Huawei]
pki enroll-certificate testb
Create a challenge password. You will need to verbally provide this password to
the CA Administrator in order to revoke your certificate.
For security reasons your password will not be saved in the configuration. Plea
se make a note of it.
Choice no password ,please enter the enter-key.
Please enter Password:
Start certificate enrollment ...
Certificate is enrolling now,It will take a few minutes or more.
Please waiting...
The certificate enroll successful.
Step 9
Verify the configuration.
Run the
display ike sa v2
command on RouterA and RouterB to view IKE SA information. The
command output shows that RouterA and RouterB have established an IKE SA and can ping
each other successfully.
The display on RouterA is as follows.
[Huawei]
display ike sa v2
Conn-ID Peer VPN Flag(s) Phase
---------------------------------------------------------------
898 2.2.2.1 0 RD|ST 2
895 2.2.2.1 0 RD|ST 1
Flag Description:
RD--READY ST--STAYALIVE RL--REPLACED FD--FADING TO--TIMEOUT
HRT--HEARTBEAT LKG--LAST KNOWN GOOD SEQ NO. BCK--BACKED UP
[Huawei]
The display on RouterB is as follows.
[Huawei]
display ike sa v2
Conn-ID Peer VPN Flag(s) Phase
---------------------------------------------------------------
874 1.1.1.1 0 RD 2
873 1.1.1.1 0 RD 1
Flag Description:
RD--READY ST--STAYALIVE RL--REPLACED FD--FADING TO--TIMEOUT
HRT--HEARTBEAT LKG--LAST KNOWN GOOD SEQ NO. BCK--BACKED UP
Ping RouterB from RouterA. RouterA can ping RouterB successfully.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
12 PKI Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
259