493
Examples
# Create a manual IPsec profile named
profile1
.
<Sysname> system-view
[Sysname] ipsec profile profile1 manual
[Sysname-ipsec-profile-manual-profile1]
# Create an IKE-based IPsec profile named
profile1
.
<Sysname> system-view
[Sysname] ipsec profile profile1 isakmp
[Sysname-ipsec-profile-isakmp-profile1]
Related commands
display ipsec profile
ipsec redundancy enable
Use
ipsec redundancy enable
to enable IPsec redundancy.
Use
undo ipsec redundancy enable
to disable IPsec redundancy.
Syntax
ipsec redundancy enable
undo ipsec redundancy enable
Default
IPsec redundancy is disabled.
Views
System view
Predefined user roles
network-admin
Usage guidelines
With IPsec redundancy enabled, the system synchronizes the following information from the active
device to the standby device at configurable intervals:
•
Lower bound values of the IPsec anti-replay window for inbound packets.
•
IPsec anti-replay sequence numbers for outbound packets.
The synchronization ensures uninterrupted IPsec traffic forwarding and anti-replay protection when
the active device fails.
To configure synchronization intervals, use the
redundancy replay-interval
command.
Examples
# Enable IPsec redundancy.
<Sysname> system-view
[Sysname] ipsec redundancy enable
Related commands
redundancy replay-interval
ipsec sa global-duration
Use
ipsec sa global-duration
to configure the global IPsec SA lifetime.
Summary of Contents for FlexNetwork MSR Series
Page 1005: ...987 ...