Configuring Ipsec For Ipv6 Routing Protocols; Configuration Task List; Configuring A Manual Ipsec Profile - HP FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Step
2.
Enter interface view.
3.
Configure the DF bit of
IPsec packets on the
interface.
To configure the DF bit of IPsec packets globally:
Step
1.
Enter system view.
2.
Configure the DF bit of
IPsec packets globally.

Configuring IPsec for IPv6 routing protocols

Configuration task list

Complete the following tasks to configure IPsec for IPv6 routing protocols:
Tasks at a glance
(Required.)
(Required.)
(Required.) Applying the IPsec profile to an IPv6 routing protocol (see Layer 3—IP Routing Configuration
Guide)
(Optional.)
Enabling logging of IPsec packets
(Optional.)
Configuring SNMP notifications for IPsec

Configuring a manual IPsec profile

A manual IPsec profile is similar to a manual IPsec policy. The difference is that an IPsec profile is
uniquely identified by a name and it does not support ACL configuration. A manual IPsec profile
specifies the IPsec transform set used for protecting data flows, and the SPIs and keys used by the
SAs.
When you configure a manual IPsec profile, make sure the IPsec profile configuration at both tunnel
ends meets the following requirements:
The IPsec transform set specified for the IPsec profile at the two tunnel ends must have the
same security protocol, encryption and authentication algorithms, and packet encapsulation
mode.
The local inbound and outbound IPsec SAs must have the same SPI and key.
The IPsec SAs on the devices in the same scope must have the same key. The scope is defined
by protocols. For OSPF, the scope consists of OSPF neighbors or an OSPF area. For RIPng,
Command
interface interface-type
interface-number
ipsec df-bit { clear | copy | set }
Command
system-view
ipsec global-df-bit { clear | copy |
set }
Configuring an IPsec transform set
Configuring a manual IPsec profile
298
Remarks
N/A
By default, the interface uses the
global DF bit setting.
Remarks
N/A
By default, IPsec copies the DF
bit in the original IP header to the
new IP header.

Advertisement

Table of Contents
loading

Table of Contents