483
Syntax
ipsec
apply
{
ipv6-policy
|
policy
}
policy-name
undo
ipsec apply
{
ipv6-policy
|
policy
}
Default
No IPsec policy is applied to an interface.
Views
Interface view
Predefined user roles
network-admin
Parameters
ipv6-policy
: Specifies an IPv6 IPsec policy.
policy
: Specifies an IPv4 IPsec policy.
policy-name
: Specifies an IPsec policy name, a case-insensitive string of 1 to 63 characters.
Usage guidelines
On an interface, you can apply a maximum of two IPsec policies: one IPv4 IPsec policy and one IPv6
IPsec policy.
An IKE-based IPsec policy can be applied to multiple interfaces. A manual IPsec policy can be
applied to only one interface.
Examples
# Apply the IPsec policy
policy1
to interface GigabitEthernet 1/0/1.
<Sysname> system-view
[Sysname] interface gigabitethernet 1/0/1
[Sysname-GigabitEthernet1/0/1] ipsec apply policy policy1
Related commands
display
ipsec
{
ipv6-policy
|
policy
}
ipsec
{
ipv6-policy
|
policy
}
ipsec decrypt-check enable
Use
ipsec decrypt-check enable
to enable ACL checking for de-encapsulated IPsec packets.
Use
undo ipsec decrypt-check
to disable ACL checking for de-encapsulated IPsec packets.
Syntax
ipsec decrypt-check enable
undo ipsec decrypt-check enable
Default
ACL checking for de-encapsulated IPsec packets is enabled.
Views
System view
Predefined user roles
network-admin
Summary of Contents for FlexNetwork MSR Series
Page 1005: ...987 ...