566CHAPTER 40: CONFIGURING IPSEC

Table 634 Enable/Disable the Host to Backup the NDEC Cards

Operation

Command

 

 

Enable the host to backup the crypto

encrypt-card backuped

cards

 

 

 

Disable the host to backup the crypto

undo encrypt-card backuped

cards

 

 

 

By default, the host is disabled to backup the crypto cards.

Defining IPSec Proposal The IPSec saved in conversion mode needs a special security protocol and encryption/authentication algorithm to provide various security parameters for the IPSec negotiation security confederation. Both ends must use the same conversion mode for successfully negotiating IPSec security confederation.

Define IPSec proposal

Multiple IPSec proposals can be defined, and then one or many of them can be quoted in one security policy. The same security protocol and algorithm conversion must be configured at both ends when security confederation is manually created.

If you modify the conversion mode after successful security confederation negotiation, this security confederation will still use the former conversion mode, while the newly negotiated security confederation will use the new conversion mode. To make the new setting effective at once, it is necessary to use the reset ipsec sa command to clear part or all of the SA database.

Perform the following configurations in system view.

Table 635 Define IPSec Proposal

Operation

Command

 

 

Define IPSec proposal to enter the view of

ipsec proposal proposal-name

IPSec proposal view (applicable to IPSec

 

software)

 

 

 

Delete IPSec proposal view (applicable to

undo ipsec proposal proposal-name

IPSec software)

 

 

 

Define the IPSec proposal and enter view

crypto ipsec card-proposal

of IPSec proposal view (applicable to

proposal-name

crypto card)

 

 

 

Delete IPSec proposal view of the crypto

undo crypto ipsec card-proposal

card (applicable to crypto card)

proposal-name

 

 

By default, no proposal view is configured.

Set the Mode for Security Protocol to Encapsulate IP Message

The IP message encapsulating mode selected by both ends of security tunnel must be consistent.

Configure the following in IPSec proposal view (or proposal view of crypto card).

Table 636 Set the Mode for Security Protocol to Encapsulate Messages

Operation

Command

 

 

Set the mode for security protocol to

encapsulation-mode { transport

encapsulate messages (applicable to IPSec

tunnel }

software and crypto card)

 

Page 570
Image 570
3Com 10014299 manual Define IPSec proposal, By default, no proposal view is configured, Define IPSec Proposal