EasyManuals Logo

HPE FlexNetwork 5510 HI Series Security Configuration Guide

HPE FlexNetwork 5510 HI Series
551 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #280 background imageLoading...
Page #280 background image
267
Step
Command
Remarks
authentication algorithm for AH:
• In non-FIPS mode:
ah authentication-algorithm
{ md5 | sha1 } *
• In FIPS mode:
ah authentication-algorithm
sha1
(Release 1121 and later.) Specify the
authentication algorithm for AH:
• In non-FIPS mode:
ah authentication-algorithm
{ aes-xcbc-mac | md5 | sha1 |
sha256 | sha384 | sha512 } *
• In FIPS mode:
ah authentication-algorithm
{ sha1 | sha256 | sha384 |
sha512 } *
5. Specify the mode in
which the security
protocol encapsulates
IP packets.
encapsulation-mode
{
transport
|
tunnel
}
By default, the security protocol
encapsulates IP packets in
tunnel mode.
The transport mode applies only
when the source and destination
IP addresses of data flows match
those of the IPsec tunnel.
IPsec for IPv6 routing protocols
supports only the transport
mode.
6.
(Optional.) Enable the
Perfect Forward
Secrecy (PFS) feature
for the IPsec policy.
• In non-FIPS mode:
pfs { dh-group1 | dh-group2 |
dh-group5 | dh-group14 |
dh-group19 | dh-group20 |
dh-group24 }
• In FIPS mode:
pfs { dh-group14 | dh-group24 |
dh-group19 | dh-group20 }
By default, the PFS feature is not
used for SA negotiation.
For more information about PFS,
see "Configuring IKE."
T
he security level of the
Diffie-Hellman (DH) group of the
initiator must be higher than or
equal to that of the responder.
The end without the PFS feature
performs SA negotiation
according
to the PFS
requirements of the peer end.
The DH groups 19 and 20 are
available only for IKEv2.
7.
(Optional.) Enable the
Extended Sequence
Number (ESN) feature.
esn enable
[
both
]
B
y default, the ESN feature is
disabled.
Configuring a manual IPsec policy
In a manual IPsec policy, the parameters are configured manually, such as the keys, the SPIs, and
the IP addresses of the two ends in tunnel mode.
Configuration restrictions and guidelines
Make sure the IPsec configuration at the two ends of an IPsec tunnel meets the following
requirements:

Table of Contents

Other manuals for HPE FlexNetwork 5510 HI Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HPE FlexNetwork 5510 HI Series and is the answer not in the manual?

HPE FlexNetwork 5510 HI Series Specifications

General IconGeneral
BrandHPE
ModelFlexNetwork 5510 HI Series
CategorySwitch
LanguageEnglish

Related product manuals