HP 6125XLG R2306-HP 6125XLG Blade Switch Security Command Reference - Page 274

remote-address, obtains the latest IP address of the host.

Page 274 highlights

[Sysname] ipsec policy policy1 100 manual [Sysname-ipsec-policy-manual-policy1-100] qos pre-classify remote-address Use remote-address to configure the remote IP address for the IPsec tunnel. Use undo remote-address to restore the default. Syntax remote-address { [ ipv6 ] host-name | ipv4-address | ipv6 ipv6-address } undo remote-address { [ ipv6 ] host-name | ipv4-address | ipv6 ipv6-address } Default No remote IP address is specified for the IPsec tunnel. Views IPsec policy view, IPsec policy template view Predefined user roles network-admin Parameters ipv6: Specifies a remote IPv6 address. Without this keyword, you specify an IPv4 address or host name. hostname: Specifies the remote host name, a case-sensitive string of 1 to 255 characters. The host name can be resolved to an IP address by the DNS server. ipv4-address: Specifies a remote IPv4 address. ipv6-address: Specifies a remote IPv6 address. Usage guidelines This remote IP address configuration is required on the IKE negotiation initiator and optional on the responder. A manual IPsec policy does not support DNS. Therefore, you must specify a remote IP address rather than a remote host name for the manual IPsec policy. If you configure a remote host name, the following scenarios apply: • If the host name is resolved by the DNS server, the local end sends a request to the DNS server to obtain the latest IP address corresponding to the host name when the domain name resolution period expires. The resolution period is defined by the DNS server and restarts after the local end obtains the latest IP address of the host. • If the host name is resolved by the ip host command and you change the IP address of the remote host, you must reconfigure the remote host name in the IPsec policy or IPsec policy template by using the remote-address command. Otherwise, the local end cannot obtain the latest IP address of the remote host. For example, the local end has a static domain name resolution entry, which maps the host name test to the IP address 1.1.1.1. Configure the following commands: # Configure the remote host name to test for the IPsec tunnel in the IPsec policy policy1. [Sysname] ipsec policy policy1 1 isakmp [Sysname-ipsec-policy-isakmp-policy1-1] remote-address test 265

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321

265
[Sysname] ipsec policy policy1 100 manual
[Sysname-ipsec-policy-manual-policy1-100] qos pre-classify
remote-address
Use
remote-address
to configure the remote IP address for the IPsec tunnel.
Use
undo remote-address
to restore the default.
Syntax
remote-address
{ [
ipv6
]
host-name
|
ipv4-address
|
ipv6
ipv6-address
}
undo
remote-address
{ [
ipv6
]
host-name
|
ipv4-address
|
ipv6
ipv6-address
}
Default
No remote IP address is specified for the IPsec tunnel.
Views
IPsec policy view, IPsec policy template view
Predefined user roles
network-admin
Parameters
ipv6
: Specifies a remote IPv6 address. Without this keyword, you specify an IPv4 address or host name.
hostname
: Specifies the remote host name, a case-sensitive string of 1 to 255 characters. The host name
can be resolved to an IP address by the DNS server.
ipv4-address
: Specifies a remote IPv4 address.
ipv6-address
: Specifies a remote IPv6 address.
Usage guidelines
This remote IP address configuration is required on the IKE negotiation initiator and optional on the
responder.
A manual IPsec policy does not support DNS. Therefore, you must specify a remote IP address rather than
a remote host name for the manual IPsec policy.
If you configure a remote host name, the following scenarios apply:
If the host name is resolved by the DNS server, the local end sends a request to the DNS server to
obtain the latest IP address corresponding to the host name when the domain name resolution
period expires. The resolution period is defined by the DNS server and restarts after the local end
obtains the latest IP address of the host.
If the host name is resolved by the
ip host
command and you change the IP address of the remote
host, you must reconfigure the remote host name in the IPsec policy or IPsec policy template by using
the
remote-address
command. Otherwise, the local end cannot obtain the latest IP address of the
remote host.
For example, the local end has a static domain name resolution entry, which maps the host name
test
to
the IP address 1.1.1.1. Configure the following commands:
# Configure the remote host name to
test
for the IPsec tunnel in the IPsec policy
policy1
.
[Sysname] ipsec policy policy1 1 isakmp
[Sysname-ipsec-policy-isakmp-policy1-1] remote-address test