EasyManuals Logo

HP 3600 v2 Series Configuration Guide

HP 3600 v2 Series
449 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #308 background imageLoading...
Page #308 background image
295
Ste
p
Command
Remarks
1. Enter system view. system-view N/A
2. Create an IKE proposal and
enter its view.
ike proposal proposal-number N/A
3. Specify an encryption
algorithm for the IKE
proposal.
encryption-algorithm aes-cbc
[ key-length ]
Optional.
The default is AES-CBC-128.
4. Specify an authentication
method for the IKE proposal.
authentication-method { pre-share
| rsa-signature }
Optional.
Pre-shared key by default.
5. Specify an authentication
algorithm for the IKE
proposal.
authentication-algorithm { sha
|
sha256
}
Optional.
HMAC-SHA256 by default.
6. Specify a DH group for key
negotiation in phase 1.
dh group14
Optional.
group14 (the 2048-bit DH group)
by default.
7. Set the ISAKMP SA lifetime for
the IKE proposal.
sa duration seconds
Optional.
86400 seconds by default.
NOTE:
Before an ISAKMP SA expires, IKE negotiates a new SA to replace it. DH calculation in IKE negotiation
takes time, especially on low-end devices. To prevent SA updates from influencing normal
communication, set the lifetime greater than 10 minutes.
Configuring an IKE peer
For an IPsec policy that uses IKE, you must configure an IKE peer by performing the following tasks:
• Specify the IKE negotiation mode (main mode) for the local end to use in IKE negotiation phase 1.
When acting as the IKE negotiation responder, the local end uses the IKE negotiation mode of the
remote end.
• Specify the IKE proposals for the local end to use when acting as the IKE negotiation initiator. When
acting as the responder, the local end uses the IKE proposals configured in system view for
negotiation.
• Configure a pre-shared key for pre-shared key authentication or a PKI domain for digital signature
authentication.
• Specify the ID type for the local end to use in IKE negotiation phase 1. With pre-shared key
authentication, the ID type must be IP address for main mode IKE negotiation.
• Specify the name or IP address of the local security gateway. You perform this task only when you
want to specify a special address, for example, a loopback interface address, as the local security
gateway address.
• Specify the name or IP address of the remote security gateway. For the local end to initiate IKE
negotiation, you must specify the name or IP address of the remote security gateway on the local
end so the local end can find the remote end.
• Enable NAT traversal. If there is NAT gateway on the path for tunneling, you must configure NAT
traversal at the two ends of the IPsec tunnel, because one end may use a public address while the
other end uses a private address.

Table of Contents

Other manuals for HP 3600 v2 Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HP 3600 v2 Series and is the answer not in the manual?

HP 3600 v2 Series Specifications

General IconGeneral
BrandHP
Model3600 v2 Series
CategorySwitch
LanguageEnglish

Related product manuals