HP StorageWorks 8/20q HP StorageWorks 8/20q Fibre Channel Switch Command Line - Page 174

ipsec policy, Table 15 Policy configuration parameters

Page 174 highlights

ipsec policy Description Manages policies in the Security Policy database. Authority Admin session and an Ipsec Edit session Syntax ipsec policy copy [policy_source] [policy_destination] create [policy] delete [policy] edit [policy] list [option] rename [policy_old] [policy_new] Operands copy [policy_source] [policy_destination] Creates a new policy named [policy_destination] and copies the configuration into it from the policy given by [policy_source]. You must enter the ipsec save command afterwards to save your changes. [policy_destination] must not begin with DynamicSP_, which is reserved for dynamic policies. create [policy] Creates a policy with the name given by [policy]. A policy name must begin with a letter and be no longer than 32 characters. Valid characters are alphanumeric, _, $, ^, and -. The Security Policy database supports a maximum of 128 user-defined policies. You must enter the ipsec save command afterwards to save your changes. Table 15 describes the policy parameters: Table 15 Policy configuration parameters Parameter Description SourceAddress SourcePort DestinationAddress DestinationPort Protocol ICMPv6 Type Description Description of the policy IP address (version 4 or 6) or DNS host name of the host, switch, or gateway from which data originates Source port number in the range 1-65535 IP address (version 4 or 6) or DNS host name of the host, switch, or gateway receiving data. If you specified an IP address for the SourceAddress, the DestinationAddress must use the same IP version format. Destination port number in the range 1-65535 Protocol or application to which to apply IP security. Enter an operand for one of the following protocols or an integer in the range 0-255: • Internet Control Message Protocol for IPv4 (ICMP) • Internet Control Message Protocol for IPv6 (ICMP6) • Internet Protocol, version 4 (IPv4) • Transmission Control Protocol (TCP) • User Datagram Protocol (UDP) • Any protocol ICMP number (0-255). You are prompted for this parameter only if you specify ICMP6 for the Protocol parameter. 174 Command reference

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332

174
Command reference
ipsec policy
Description
Manages policies in the Security Policy database.
Authority
Admin session and an Ipsec Edit session
Syntax
ipsec policy
copy [policy_source] [policy_destination]
create [policy]
del
ete [policy]
edit [policy]
list
[option]
rename [policy_old] [policy_new]
Operands
copy [policy_source] [policy_destination]
Creates a new policy named [policy_destination] and copies the configuration into it from the
policy given by [policy_source]. You must enter the
ipsec save
command afterwards to save
your changes. [policy_destination] must not begin with
DynamicSP_
, which is reserved for
dynamic policies.
create [policy]
Creates a policy with the name given by [policy]. A policy name must begin with a letter and be
no longer than 32 characters. Valid characters are alphanumeric, _, $, ^, and -. The Security
Policy database supports a maximum of 128 user-defined policies. You must enter the
ipsec save
command afterwards to save your changes.
Table 15
describes the policy
parameters:
Table 15
Policy configuration parameters
Parameter
Description
Description
Description of the policy
SourceAddress
IP address (version 4 or 6) or DNS host name of the host, switch, or
gateway from which data originates
SourcePort
Source port number in the range
1
65535
DestinationAddress
IP address (version 4 or 6) or DNS host name of the host, switch, or
gateway receiving data. If you specified an IP address for the
SourceAddress
, the
DestinationAddress
must use the same
IP version format.
DestinationPort
Destination port number in the range
1
65535
Protocol
Protocol or application to which to apply IP security. Enter an
operand for one of the following protocols or an integer in the
range
0
255
:
Internet Control Message Protocol for IPv4 (ICMP)
Internet Control Message Protocol for IPv6 (ICMP6)
Internet Protocol, version 4 (IPv4)
Transmission Control Protocol (TCP)
User Datagram Protocol (UDP)
Any protocol
ICMPv6 Type
ICMP number (0–255). You are prompted for this parameter only if
you specify ICMP6 for the Protocol parameter.