HP 6125XLG R2306-HP 6125XLG Blade Switch Security Command Reference - Page 268

ipsec profile, ipsec sa global-duration

Page 268 highlights

• ipsec { ipv6-policy | policy } (system view) • ipsec { ipv6-policy | policy } isakmp template ipsec profile Use ipsec profile to create an IPsec profile, and enter IPsec profile view. Use undo ipsec profile to delete the specified IPsec profile. Syntax ipsec profile profile-name [ manual ] undo ipsec profile profile-name Default No IPsec profile is created. Views System view Predefined user roles network-admin Parameters profile-name: Specifies a name for the IPsec profile, a case-sensitive string of 1 to 63 characters. manual: Specifies the IPsec SA setup mode as manual. Usage guidelines When you create an IPsec profile, you must specify the IPsec SA setup mode (manual). When you enter the view of an existing IPsec profile, you do not need to specify the IPsec SA setup mode. An IPsec profile is similar to a manual IPsec policy. It is dedicatedly used for IPsec protection for application protocols, including OSPFv3, IPv6 BGP, and RIPng. Examples # Create an IPsec profile named profile1. system-view [Sysname] ipsec profile profile1 manual [Sysname-ipsec-profile-profile1] Related commands display ipsec profile ipsec sa global-duration Use ipsec sa global-duration to configure the global IPsec SA lifetime. Use undo ipsec sa global-duration to restore the default. Syntax ipsec sa global-duration { time-based seconds | traffic-based kilobytes } undo ipsec sa global-duration { time-based | traffic-based } 259

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321

259
ipsec
{
ipv6-policy
|
policy
} (system view)
ipsec
{
ipv6
-
policy
|
policy
}
isakmp
template
ipsec profile
Use
ipsec profile
to create an IPsec profile, and enter IPsec profile view.
Use
undo ipsec profile
to delete the specified IPsec profile.
Syntax
ipsec profile
profile-name
[
manual
]
undo
ipsec
profile
profile-name
Default
No IPsec profile is created.
Views
System view
Predefined user roles
network-admin
Parameters
profile-name
: Specifies a name for the IPsec profile, a case-sensitive string of 1 to 63 characters.
manual
: Specifies the IPsec SA setup mode as manual.
Usage guidelines
When you create an IPsec profile, you must specify the IPsec SA setup mode (
manual
). When you enter
the view of an existing IPsec profile, you do not need to specify the IPsec SA setup mode.
An IPsec profile is similar to a manual IPsec policy. It is dedicatedly used for IPsec protection for
application protocols, including OSPFv3, IPv6 BGP, and RIPng.
Examples
# Create an IPsec profile named
profile1
.
<Sysname> system-view
[Sysname] ipsec profile profile1 manual
[Sysname-ipsec-profile-profile1]
Related commands
display ipsec profile
ipsec sa global-duration
Use
ipsec sa global-duration
to configure the global IPsec SA lifetime.
Use
undo ipsec sa global-duration
to restore the default.
Syntax
ipsec sa global-duration
{
time-based
seconds
|
traffic-based
kilobytes
}
undo ipsec sa global-duration
{
time-based
|
traffic-based
}