HP 12500 Series Configuration Manual page 185

Routing
Table of Contents

Advertisement

Step
3.
Assign an ACL to the
IPsec policy.
4.
Assign an IPsec proposal
to the IPsec policy.
5.
Configure the local
address and the remote
address of the IPsec
tunnel.
6.
Configure an SPI for an
SA.
Command
security acl acl-number
proposal proposal-name
Configure the local address of
the IPsec tunnel:
tunnel local ip-address
Configure the remote address
of the IPsec tunnel:
tunnel remote ip-address
sa spi { inbound | outbound } { ah
| esp } spi-number
175
Remarks
Not needed for IPsec policies to be
applied to IPv6 routing protocols and
required for other applications.
By default, an IPsec policy references no
ACL.
The ACL supports match criteria of the
VPN attribute.
An IPsec policy can reference only one
ACL. If you apply multiple ACLs to an
IPsec policy, only the last one takes
effect.
By default, an IPsec policy references no
IPsec proposal.
A manual IPsec policy can reference only
one IPsec proposal. To change an IPsec
proposal for an IPsec policy, you must
remove the reference first.
Not needed for IPsec policies to be
applied to IPv6 routing protocols and
required for other applications.
By default, the tunnel local and remote
addresses are not configured.
You can configure the tunnel local and
remote addresses only in FIPS mode.
By default, no SPI is configured for an
SA.

Advertisement

Table of Contents
loading

Table of Contents