HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 235

Optional. Con IKE, address of the interface that

Page 235 highlights

Step Command Remarks 3. Configure a peer ID. match remote { certificate policy-name | identity { address { { ipv4-address [ mask | mask-length ] | range low-ipv4-address high-ipv4-address } | ipv6 { ipv6-address [ prefix-length ] | range low-ipv6-address high-ipv6-address } } [ vpn-instance vpn-name ] | fqdn fqdn-name | user-fqdn user-fqdn-name } } By default, an IKE profile has no peer ID. Each of the two peers must have at least one peer ID configured. 4. Specify the keychain for pre-shared key authentication. keychain keychain-name Configure either or both of the commands as required. By default, no IKE keychain is specified for an IKE profile. 5. Specify the IKE negotiation mode for phase 1. • In non-FIPS mode: exchange-mode { aggressive | main } • In -FIPS mode: exchange-mode main By default, the main mode is used during IKE negotiation phase 1. 6. Specify the IKE proposals for the IKE profile to reference. proposal proposal-number& By default, an IKE profile references no IKE proposals and uses the IKE proposals configured in system view for IKE negotiation. 7. Configure the local ID. local-identity { address { ipv4-address | ipv6 ipv6-address } | dn | fqdn [ fqdn-name ] | user-fqdn [ user-fqdn-name ] } By default, no local ID is configured for an IKE profile, and an IKE profile uses the local ID configured in system view. If no local ID is configured in system view either, the IP address of the interface that the IPsec policy or IPsec policy template is applied to is used as the local ID. 8. (Optional.) Configure IKE DPD. dpd interval interval-seconds [ retry seconds ] { on-demand | periodic } By default, the IKE DPD function is not configured for an IKE profile and an IKE profile uses the DPD settings configured in system view. If the IKE DPD function is not configured in system either, the device does not perform dead IKE peer detection. 9. (Optional.) Specify a local interface or IP address that the IKE profile can be applied to. match local address { interface-type interface-number | { ipv4-address | ipv6 ipv6-address } [ vpn-instance vpn-name ] } By default, an IKE profile can be applied to any local interface or IP address. 226

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

226
Step
Command
Remarks
3.
Configure a peer ID.
match remote
{
certificate
policy-name
|
identity
{
address
{ {
ipv4-address
[
mask
|
mask-length
] |
range
low-ipv4-address high-ipv4-address
}
|
ipv6
{
ipv6-address
[
prefix-length
] |
range
low-ipv6-address
high-ipv6-address
} } [
vpn-instance
vpn-name
] |
fqdn
fqdn-name
|
user-fqdn
user-fqdn-name
} }
By default, an IKE profile has no
peer ID.
Each of the two peers must have
at least one peer ID configured.
4.
Specify the keychain for
pre-shared key
authentication.
keychain
keychain-name
Configure either or both of the
commands as required.
By default, no IKE keychain is
specified for an IKE profile.
5.
Specify the IKE negotiation
mode for phase 1.
In non-FIPS mode:
exchange-mode
{
aggressive
|
main
}
In -FIPS mode:
exchange-mode main
By default, the main mode is
used during IKE negotiation
phase 1.
6.
Specify the IKE proposals for
the IKE profile to reference.
proposal
proposal-number&<1-6>
By default, an IKE profile
references no IKE proposals
and uses the IKE proposals
configured in system view for
IKE negotiation.
7.
Configure the local ID.
local-identity
{
address
{
ipv4-address
|
ipv6
ipv6-address
} |
dn
|
fqdn
[
fqdn-name
] |
user-fqdn
[
user-fqdn-name
] }
By default, no local ID is
configured for an IKE profile,
and an IKE profile uses the local
ID configured in system view. If
no local ID is configured in
system view either, the IP
address of the interface that the
IPsec policy or IPsec policy
template is applied to is used as
the local ID.
8.
(Optional.) Configure IKE
DPD.
dpd interval
interval-seconds
[
retry
seconds
]
{
on-demand
|
periodic
}
By default, the IKE DPD function
is not configured for an IKE
profile and an IKE profile uses
the DPD settings configured in
system view. If the IKE DPD
function is not configured in
system either, the device does
not perform dead IKE peer
detection.
9.
(Optional.) Specify a local
interface or IP address that
the IKE profile can be
applied to.
match local address
{
interface-type
interface-number
| {
ipv4-address
|
ipv6
ipv6-address
} [
vpn-instance
vpn-name
] }
By default, an IKE profile can be
applied to any local interface or
IP address.