a. Run the ping 10.1.2.1 command on PC A to construct ping packets to match the
ACL referenced by the IPSec policy.
After the preceding operations are complete, run the display ike sa command on Router A
and Router B. SAs are generated.
----End
Summary
After IPSec policies are configured at both ends, at least one end initiates IKE negotiation. If an
IPSec policy template is used, the remote end must initiate negotiation. The SA triggering mode
can be automatic or traffic-based triggering.
Huawei AR2200-S Series Enterprise Routers
Troubleshooting 12 VPN
Issue 01 (2012-01-06) Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
382