EasyManuals Logo

HPE FlexNetwork MSR Series Comware 5 Security Configuration Guide

HPE FlexNetwork MSR Series
547 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #482 background imageLoading...
Page #482 background image
469
[KS1-gdoi-ks-group-ks1-ipsec-10] security acl name fortek
[KS1-gdoi-ks-group-ks1-ipsec-10] quit
# Specify the peer KS 200.2.2.200.
[KS1-gdoi-ks-group-ks1] peer address 200.2.2.200
# Specify the source address of sent packets as 100.1.1.100.
[KS1-gdoi-ks-group-ks1] source address 100.1.1.100
# Specify the local priority as 10000.
[KS1-gdoi-ks-group-ks1] local priority 10000
# Enable GDOI KS redundancy.
[KS1-gdoi-ks-group-ks1] redundancy enable
[KS1-gdoi-ks-group-ks1] quit
Configuring KS 2
# Configure IP addresses for interfaces. (Details not shown.)
# Configure IKE proposal 1.
<KS2> system-view
[KS2] ike proposal 1
# Specify the encryption algorithm AES-CBC 128 for IKE proposal 1.
[KS2-ike-proposal-1] encryption-algorithm aes-cbc 128
# Specify the authentication algorithm SHA1 for IKE proposal 1.
[KS2-ike-proposal-1] authentication-algorithm sha
# Specify DH group 2 for IKE proposal 1.
[KS2-ike-proposal-1] dh group2
[KS2-ike-proposal-1] quit
# Create the IKE peer toks1 for IKE negotiation with KS 1.
[KS2] ike peer toks1
# Apply IKE proposal 1 to the IKE peer.
[KS2-ike-peer-toks1] proposal 1
# Configure the pre-shared key as tempkey1 in plaintext.
[KS2-ike-peer-toks1] pre-shared-key simple tempkey1
# Specify the IP address of the IKE peer as 100.1.1.100.
[KS2-ike-peer-toks1] remote-address 100.1.1.100
[KS2-ike-peer-toks1] quit
# Create the IKE peer togm for IKE negotiation with GMs.
[KS2] ike peer togm
# Apply IKE proposal 1 to the IKE peer.
[KS2-ike-peer-togm] proposal 1
# Configure the pre-shared key as tempkey1 in plaintext.
[KS2-ike-peer-togm] pre-shared-key simple tempkey1
[KS2-ike-peer-togm] quit
# Create an IPsec transform set fortek.
[KS2] ipsec transform-set fortek
# Specify the ESP protocol for the IPsec transform set fortek.
[KS2-ipsec-transform-set-fortek] transform esp

Table of Contents

Other manuals for HPE FlexNetwork MSR Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HPE FlexNetwork MSR Series and is the answer not in the manual?

HPE FlexNetwork MSR Series Specifications

General IconGeneral
BrandHPE
ModelFlexNetwork MSR Series
CategoryNetwork Router
LanguageEnglish

Related product manuals