HP 6125XLG R2306-HP 6125XLG Blade Switch Security Command Reference - Page 266

ipsec { ipv6-policy | policy } local-address, Specifies an IPv4 IPsec policy.

Page 266 highlights

ipsec { ipv6-policy | policy } local-address Use ipsec { ipv6-policy | policy } local-address to bind an IPsec policy to a source interface. Use undo ipsec { ipv6-policy | policy } local-address to remove the bindings of IPsec policies and source interfaces. Syntax ipsec { ipv6-policy | policy } policy-name local-address interface-type interface-number undo ipsec { ipv6-policy | policy } policy-name local-address Default No IPsec policy is bound to a source interface. Views System view Predefined user roles network-admin Parameters ipv6-policy: Specifies an IPv6 IPsec policy. policy: Specifies an IPv4 IPsec policy. policy-name: Name of an IPsec policy, a case-sensitive string of 1 to 63 characters. local-address interface-type interface-number: Specifies the shared source interface by its type and number. Usage guidelines For high availability, two interfaces may operate in backup or load sharing mode. After an IPsec policy is applied to the two interfaces, they negotiate with their peers to establish IPsec SAs respectively. When one interface fails and a link failover occurs, the other interface needs to take some time to re-negotiate SAs, resulting in service interruption. To solve these problems, bind a source interface to an IPsec policy and apply the policy to both interfaces. This enables the two physical interfaces to use the same source interface to negotiate IPsec SAs. As long as the source interface is up, the negotiated IPsec SAs will not be removed and will keep working, regardless of link failover. After an IPsec policy is applied to a service interface and IPsec SAs have been established, if you bind the IPsec policy to a source interface, the existing IPsec SAs are deleted. Only the IKE-based IPsec policies can be bound to a source interface. An IPsec policy can be bound to only one source interface. To bind an IPsec policy to another source interface, you must first remove the current binding. A source interface can be bound to multiple IPsec policies. HP recommends using a stable interface, such as a loopback interface, as a source interface. Examples # Bind the IPsec policy map to source interface Loopback 11. system-view [Sysname] ipsec policy map local-address loopback 11 257

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321

257
ipsec { ipv6-policy | policy } local-address
Use
ipsec
{
ipv6-policy
|
policy
}
local-address
to bind an IPsec policy to a source interface.
Use
undo ipsec
{
ipv6-policy
|
policy
}
local-address
to remove the bindings of IPsec policies and source
interfaces.
Syntax
ipsec
{
ipv6-policy
|
policy
}
policy-name
local-address
interface-type interface-number
undo
ipsec
{
ipv6-policy
|
policy
}
policy-name
local-address
Default
No IPsec policy is bound to a source interface.
Views
System view
Predefined user roles
network-admin
Parameters
ipv6-policy
: Specifies an IPv6 IPsec policy.
policy
: Specifies an IPv4 IPsec policy.
policy-name
: Name of an IPsec policy, a case-sensitive string of 1 to 63 characters.
local-address
interface-type interface-number
: Specifies the shared source interface by its type and
number.
Usage guidelines
For high availability, two interfaces may operate in backup or load sharing mode. After an IPsec policy
is applied to the two interfaces, they negotiate with their peers to establish IPsec SAs respectively. When
one interface fails and a link failover occurs, the other interface needs to take some time to re-negotiate
SAs, resulting in service interruption.
To solve these problems, bind a source interface to an IPsec policy and apply the policy to both interfaces.
This enables the two physical interfaces to use the same source interface to negotiate IPsec SAs. As long
as the source interface is up, the negotiated IPsec SAs will not be removed and will keep working,
regardless of link failover.
After an IPsec policy is applied to a service interface and IPsec SAs have been established, if you bind
the IPsec policy to a source interface, the existing IPsec SAs are deleted.
Only the IKE-based IPsec policies can be bound to a source interface.
An IPsec policy can be bound to only one source interface. To bind an IPsec policy to another source
interface, you must first remove the current binding.
A source interface can be bound to multiple IPsec policies.
HP recommends using a stable interface, such as a loopback interface, as a source interface.
Examples
# Bind the IPsec policy
map
to source interface Loopback 11.
<Sysname> system-view
[Sysname] ipsec policy map local-address loopback 11