EasyManuals Logo

H3C MSR Series Command Reference

H3C MSR Series
1187 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #599 background imageLoading...
Page #599 background image
576
Examples
# Specify pre-shared key authentication to be used in IKE proposal 1.
<Sysname> system-view
[Sysname] ike proposal 1
[Sysname-ike-proposal-1] authentication-method pre-share
Related commands
display ike proposal
ike keychain
pre-shared-key
certificate domain
Use certificate domain to specify a PKI domain for signature authentication.
Use undo certificate domain to remove a PKI domain for signature authentication.
Syntax
certificate domain domain-name
undo certificate domain domain-name
Default
No PKI domains are specified for signature authentication.
Views
IKE profile view
Predefined user roles
network-admin
Parameters
domain-name: Specifies the name of a PKI domain, a case-insensitive string of 1 to 31 characters.
Usage guidelines
You can specify a maximum of six PKI domains for an IKE profile by executing this command
multiple times.
IKE uses the specified PKI domains for enrollment, authentication, certificate issuing, validation, and
signature. If you do not specify any PKI domains, IKE uses all PKI domains configured on the device.
Follow these restrictions and guidelines for the device to obtain the CA certificate during IKE
negotiation:
On the initiator:
If the IKE profile has a PKI domain and the automatic certificate request mode is configured
for the PKI domain, the initiator automatically obtains the CA certificate.
If the IKE profile has no PKI domain, you must manually obtain the CA certificate.
On the responder:
If main mode is used in IKE phase 1, the responder does not automatically obtain the CA
certificate. You must manually obtain the CA certificate.
If aggressive mode is used in IKE phase 1, the responder automatically obtains the CA
certificate if the following conditions are met:
A matching IKE profile is found.
An PKI domain is specified in the IKE profile.

Table of Contents

Other manuals for H3C MSR Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the H3C MSR Series and is the answer not in the manual?

H3C MSR Series Specifications

General IconGeneral
CategoryNetwork Router
IPv6 SupportYes
DimensionsVaries by model
WeightVaries by model
Product TypeModular Router
PortsVaries by model
WAN InterfacesVaries by model
FirewallYes
QoSYes
Wireless SupportVaries by model
USB PortsVaries by model
Console PortYes
Power SupplyVaries by model
RedundancyVaries by model
Operating Temperature0°C to 45°C
Storage Temperature-40°C to 70°C
Humidity5% to 95% non-condensing
SeriesMSR
CertificationsCE, FCC, RoHS

Related product manuals