ZXR10CommandManual(SecurityVolume)
showsad
showspd
sadadd
PurposeUsethiscommandtoaddIPSecsecurityassociations.
CommandModesIPSecconguration
Syntaxsadadd<source-address><destination-address>ah<spi>tran
sport<addtime><usetime><sp-index>{hmac-sha1|hmac-m
d5}<password><replay>
Syntax
Description
<source-address>IPSecsecuritytunnelsourceIPaddress,in
IPv6addressformat:X:X::X:X
<destination-addre
ss>
IPSecsecuritytunneldestinationIPaddress,
inIPv6addressformat:X:X::X:X
<spi>
IPSecsecurityparameterindex,range:
4096~10000
<addtime>
Securityassociationlifetime,range:
0~4294967295,thesecurityassociationis
deletedafterthelifetime.Lifetime0indicates
thesecurityassociationiseffectiveforever
<usetime>
Securityassociationeffectiveusetime,range:
0~4294967295
<sp-index>
IndexforassociatingtheSPpolicy,referto
thespdaddcommand
<password>
Securityauthenticationkey,16bytesfor
hmac-md5and20bytesforhmac-sha1
authentication
<replay>Anti-replayattackwindowsize,range:0~255
Instructions�Theplatformversion4.6.02andupgradeversionssupportthis
command.
�ThiscommandisusedtoaddIPSecsecurityassociations.
Securitymanagementistheassembleoftunnel/transmission
mode,security/authenticationalgorithm,encryption/au-
thenticationkeyandlifetimeinvolvedintheIPSecsecurity
protection.Thesecurityassociationisunidirectionaland
varioussecurityprotocols(AH/ESP)adoptdifferentsecurity
associations.
�Forthenon-permanentlyeffectivedynamicsecurityassocia-
tion,whenthewritecommandisusedtosavetheroutercon-
guration,thecongurationrelatedwithsecurityassociationis
notsavedintheFLASHanditwillnottakeeffectafterthesys-
temisrestarted.Iftheconguredsecurityassociationneeds
tobeeffectiveafterthesystemisrestarted,thesecurityasso-
ciationmustbeconguredtobepermanentlyeffective.
84CondentialandProprietaryInformationofZTECORPORATION