Chapter7IPSecIPv6NetworkSecurityCommands
ExampleIftheIPSechmac-md5authenticationprotectionofOSPFv3needs
tobeperformedbetweentherouter3ffe::01(link-localaddress:
fe80::2d0:d0ff:fec0:680)andtherouter3ffe::02(link-localad-
dress:fe80::2d0:d0ff:fec4:ff40),thecongurationoftheoutgo-
ingsecurityassociationontherouter3ffe::01iddisplayedasfol-
lows:
ZXR10(config)#ipsec
ZXR10(config-ipsec)#spdaddfe80::2d0:d0ff:fec0:680/64
ff02::5/64ospfoutipsecahtransportuse4
ZXR10(config-ipsec)#sadaddfe80::2d0:d0ff:fec0:680ff02::5
ah5000trans1234561234504hmac-md5123456789abcdef080
Related
Commands
ipsec
sadclear
saddelete
saddelall
sadflush
spdadd
spddelete
spdflush
showsad
showspd
sadclear
PurposeUsethiscommandtoresetIPSecsecurityassociationdynamicpa-
rameters,suchasthecountofthelifetimeandappingwindows.
CommandModesIPSecconguration
Syntaxsadclear<source-address><destination-address>ah[<spi>]
Syntax
Description
<source-address>IPSecsecuritytunnelsourceIPaddress,in
IPv6addressformat:X:X::X:X
<destination-addre
ss>
IPSecsecuritytunneldestinationIPaddress,
inIPv6addressformat:X:X::X:X
<spi>
IPSecsecurityparameterindex,range:
4096~10000
Instructions�Theplatformversion4.6.02andupgradeversionssupportthe
command.
�ThiscommandisusedtoresetsIPSecsecurityassociationdy-
namicparameters,suchasthecountofthelifetimeandap-
pingwindows.Andthismakesthesecurityassociationbeused
again.Ifthereisno<spi>parameter ,allsecurityassociations
meetingtheconditionswillbereset.
ExampleThisexampledescribeshowtoresetalldynamicparametersof
thesecurityassociationadoptingsecurityprotocolAHwiththe
sourceIPv6addressasfe80::2d0:d0ff:fec0:680,destinationIPv6
addressasfe80::2d0:d0ff:fec4:ff40.
CondentialandProprietaryInformationofZTECORPORATION85