269
successfully receives and de-encapsulates the packet, it establishes an IPv6 BGP peer relationship
with Device A and learns IPv6 BGP routes from Device A. If Device B receives but fails to
de-encapsulate the packet, or receives a packet not protected by IPsec, it discards the packet.
To configure IPsec for IPv6 BGP packets (IPv6 unicast/multicast address family):
1. Enter system view.
system-view
N/A
2. Configure an IPsec
transform set and a manual
IPsec profile.
See Security Configuration Guide
.
By default, no IPsec transform set
or manual IPsec profile exists.
3. Enter BGP instance view or
BGP-VPN instance view.
• Enter BGP instance view:
bgp as-number [ instance
instance-name ]
• Enter BGP-VPN instance
view:
a. bgp as-number
[ instance
instance-name ]
b. ip vpn-instance
N/A
4. Apply the IPsec profile to an
IPv6 BGP peer or peer
group.
peer
{ group-name | ipv6-address
[ prefix-length ] }
ipsec-profile
profile-name
By default, no IPsec profile is
configured for any IPv6 BGP peer
or peer group.
This command supports only
IPsec profiles in manual mode.
Disabling BGP to establish a session to a peer or peer group
This task enables you to temporarily tear down the BGP session to a peer or peer group. Then you
can perform network upgrade and maintenance without needing to delete and reconfigure the peer
or peer group. To recover the session, execute the undo peer ignore command.
To disable BGP to establish a session to a peer or peer group (IPv4 unicast/multicast address
family):
1. Enter system view.
system-view
N/A
2. Enter BGP instance view or
BGP-VPN instance view.
• Enter BGP instance view:
bgp as-number [ instance
instance-name ]
• Enter BGP-VPN instance
view:
a. bgp as-number
[ instance
instance-name ]
b. ip vpn-instance
N/A
3. Disable BGP to establish a
session to a peer or peer
group.
peer
{ group-name | ipv4-address
[ mask-length ] }
ignore
By default, BGP can establish a
session to a peer or peer group.
To disable BGP to establish a session to a peer or peer group (IPv6 unicast/multicast address
family):