EasyManuals Logo

HPE MSR3000 User Manual

HPE MSR3000
371 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #178 background imageLoading...
Page #178 background image
72
ï‚¡ Before the device sends data, it identifies the time interval for which the last IPsec packet
has been received from the peer. If the time interval exceeds the DPD interval, it sends a
DPD message to the peer to detect its liveliness.
ï‚¡ If the device has no data to send, it never sends DPD messages.
If you configure IKEv2 DPD in both IKEv2 profile view and system view, the IKEv2 DPD settings in
IKEv2 profile view apply. If you do not configure IKEv2 DPD in IKEv2 profile view, the IKEv2 DPD
settings in system view apply.
To configure global IKEv2 DPD:
Step
Command
Remarks
1. Enter system view.
system-view
N/A
2. Configure global IKEv2
DPD.
ikev2 dpd interval
interval [
retry
seconds ] {
on-demand
|
periodic
}
By default, global DPD is
disabled.
Configuring the IKEv2 NAT keepalive feature
Configure this feature on the IKEv2 gateway behind the NAT device. The gateway then sends NAT
keepalive packets regularly to its peer to keep the NAT session alive, so that the peer can access the
device.
The NAT keepalive interval must be shorter than the NAT session lifetime.
This feature takes effect after the device detects the NAT device.
To configure the IKEv2 NAT keepalive feature:
Step
Command
Remarks
1. Enter system view.
system-view
N/A
2. Set the IKEv2 NAT keepalive
interval.
ikev2 nat-keepalive
seconds
By default, the IKEv2 NAT
keepalive interval is 10 seconds.
Configuring IKEv2 address pools
To perform centralized management on remote users, an IPsec gateway can use an address pool to
assign private IP addresses to remote users.
You must use an IKEv2 address pool together with AAA authorization by specifying the IKEv2
address pool as an AAA authorization attribute. For more information about AAA authorization, see
"Configuring AAA."
To configure IKE address pools:
Step
Command
Remarks
1. Enter system view.
system-view
N/A

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HPE MSR3000 and is the answer not in the manual?

HPE MSR3000 Specifications

General IconGeneral
BrandHPE
ModelMSR3000
CategoryNetwork Router
LanguageEnglish

Related product manuals