HP 6125XLG R2306-HP 6125XLG Blade Switch Security Command Reference - Page 306

match local address (IKE keychain view

Page 306 highlights

dn: Uses the DN in the local certificate as the local ID. fqdn fqdn-name: Uses an FQDN as the local ID. The fqdn-name argument is a case-sensitive string of 1 to 255 characters, such as www.test.com. If you do not specify this argument, the device name configured by using the sysname command is used as the local FQDN. user-fqdn user-fqdn-name: Uses a user FQDN as the local ID. The user-fqdn-name argument is a case-sensitive string of 1 to 255 characters, such as [email protected]. If you do not specify this argument, the device name configured by using the sysname command is used as the user FQDN. Usage guidelines An IKE profile can have only one local ID. For digital signature authentication, the device can use any type of ID. If the local ID is an IP address that is different from the IP address in the local certificate, the device uses its FQDN (the device name configured by using the sysname command) instead. For pre-shared key authentication, the device can use any type of ID other than the DN. An IKE profile with no local ID specified uses the local ID configured by using the ike identity command in system view. Examples # Create IKE profile prof1. system-view [Sysname] ike profile prof1 # Set the local ID to IP address 2.2.2.2. [Sysname-ike-profile-prof1] local-identity address 2.2.2.2 Related commands • match remote • ike identity match local address (IKE keychain view) Use match local address to specify a local interface or IP address that an IKE keychain can be applied to. Use undo match local address to restore the default. Syntax match local address { interface-type interface-number | { ipv4-address | ipv6 ipv6-address } [ vpn-instance vpn-name ] } undo match local address Default An IKE keychain can be applied to any local interface or IP address. Views IKE keychain view Predefined user roles network-admin 297

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321

297
dn
: Uses the DN in the local certificate as the local ID.
fqdn
fqdn-name
: Uses an FQDN as the local ID. The
fqdn-name
argument is a case-sensitive string of 1
to 255 characters, such as www.test.com. If you do not specify this argument, the device name
configured by using the
sysname
command is used as the local FQDN.
user-fqdn
user-fqdn-name
: Uses a user FQDN as the local ID. The
user-fqdn-name
argument is a
case-sensitive string of 1 to 255 characters, such as [email protected]. If you do not specify this argument,
the device name configured by using the
sysname
command is used as the user FQDN.
Usage guidelines
An IKE profile can have only one local ID.
For digital signature authentication, the device can use any type of ID. If the local ID is an IP address that
is different from the IP address in the local certificate, the device uses its FQDN (the device name
configured by using the
sysname
command) instead.
For pre-shared key authentication, the device can use any type of ID other than the DN.
An IKE profile with no local ID specified uses the local ID configured by using the
ike identity
command
in system view.
Examples
# Create IKE profile
prof1
.
<Sysname> system-view
[Sysname] ike profile prof1
# Set the local ID to IP address
2.2.2.2
.
[Sysname-ike-profile-prof1] local-identity address 2.2.2.2
Related commands
match remote
ike identity
match local address (IKE keychain view)
Use
match local address
to specify a local interface or IP address that an IKE keychain can be applied
to.
Use
undo match local address
to restore the default.
Syntax
match local address
{
interface-type interface-number
| {
ipv4-address
|
ipv6
ipv6-address
}
[
vpn-instance
vpn-name
] }
undo match local address
Default
An IKE keychain can be applied to any local interface or IP address.
Views
IKE keychain view
Predefined user roles
network-admin