HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 241

Displaying and maintaining IKE, Main mode IKE with pre-shared key authentication configuration

Page 241 highlights

• The supported maximum number of half-open IKE SAs depends on the device's processing capability. Adjust the maximum number of half-open IKE SAs to make full use of the device's processing capability without affecting the IKE SA negotiation efficiency. • The supported maximum number of established IKE SAs depends on the device's memory space. Adjust the maximum number of established IKE SAs to make full use of the device's memory space without affecting other applications in the system. To set the limit on the number of IKE SAs: Step 1. Enter system view. 2. Set the maximum number of half-open IKE SAs and the maximum number of established IKE SAs. Command system-view ike limit { max-negotiating-sa negotiation-limit | max-sa sa-limit } Remarks N/A By default, there is no limit to the maximum number of IKE SAs. Displaying and maintaining IKE Execute display commands in any view and reset commands in user view. Task Display configuration information about all IKE proposals. Display information about the current IKE SAs. Delete IKE SAs. Command display ike proposal display ike sa [ verbose [ connection-id connection-id | remote-address [ ipv6 ] remote-address [ vpn-instance vpn-name ] ] ] reset ike sa [ connection-id connection-id ] Main mode IKE with pre-shared key authentication configuration example Network requirements As shown in Figure 77, configure an IPsec tunnel that uses IKE negotiation between Switch A and Switch B to secure the communication. Configure Switch A and Switch B to use the default IKE proposal for the IKE negotiation to set up the IPsec SA. Configure the two switches to use the pre-shared key authentication method. Figure 77 Network diagram 232

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

232
The supported maximum number of half-open IKE SAs depends on the device's processing
capability. Adjust the maximum number of half-open IKE SAs to make full use of the device's
processing capability without affecting the IKE SA negotiation efficiency.
The supported maximum number of established IKE SAs depends on the device's memory space.
Adjust the maximum number of established IKE SAs to make full use of the device's memory space
without affecting other applications in the system.
To set the limit on the number of IKE SAs:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Set the maximum number of
half-open IKE SAs and the
maximum number of
established IKE SAs.
ike limit
{
max-negotiating-sa
negotiation-limit
|
max-sa
sa-limit
}
By default, there is no limit to the
maximum number of IKE SAs.
Displaying and maintaining IKE
Execute
display
commands in any view and
reset
commands in user view.
Task
Command
Display configuration information about all IKE
proposals.
display ike proposal
Display information about the current IKE SAs.
display ike sa
[
verbose
[
connection-id
connection-id
|
remote-address
[
ipv6
]
remote-address
[
vpn-instance
vpn-name
] ] ]
Delete IKE SAs.
reset
ike
sa
[
connection-id
connection-id
]
Main mode IKE with pre-shared key authentication
configuration example
Network requirements
As shown in
Figure 77
, configure an IPsec tunnel that uses IKE negotiation between Switch A and Switch
B to secure the communication.
Configure Switch A and Switch B to use the default IKE proposal for the IKE negotiation to set up the IPsec
SA. Configure the two switches to use the pre-shared key authentication method.
Figure 77
Network diagram