546
name, a case-sensitive string of 1 to 31 characters. If the address or addresses belong to the public
network, do not specify this option.
Usage guidelines
When an end needs to select an IKE profile, it compares the peer's ID received with the peer IDs of
its local IKE profiles. If a match is found, it uses the IKE profile with the matching peer ID for IKE
negotiation.
Each IKE profile must have at least one peer ID configured. To make sure only one IKE profile is
matched for a peer, do not configure the same peer ID for two or more IKE profiles. If you configure
the same peer ID for two or more IKE profiles, which IKE profile is selected for IKE negotiation is
unpredictable.
For an IKE profile, you can configure multiple peer IDs. A peer ID configured earlier has a higher
priority.
Examples
# Create the IKE profile
prof1
.
<Sysname> system-view
[Sysname] ike profile prof1
# Configure a peer ID with the identity type of FQDN and the value of
www.test.com
.
[Sysname-ike-profile-prof1] match remote identity fqdn www.test.com
# Configure a peer ID with the identity type of IP address and the value of
10.1.1.1
.
[Sysname-ike-profile-prof1] match remote identity address 10.1.1.1
Related commands
local-identity
pre-shared-key
Use
pre-shared-key
to configure a pre-shared key.
Use
undo pre-shared-key
to delete a pre-shared key.
Syntax
In non-FIPS mode:
pre-shared-key
{
address
{
ipv4-address
[
mask
|
mask-length
] |
ipv6 ipv6-address
[
prefix-length
] } |
hostname host-name
}
key
{
cipher
|
simple
}
string
undo pre-shared-key
{
address
{
ipv4-address
[
mask
|
mask-length
] |
ipv6 ipv6-address
[
prefix-length
] } |
hostname host-name
}
In FIPS mode:
pre-shared-key
{
address
{
ipv4-address
[
mask
|
mask-length
] |
ipv6 ipv6-address
[
prefix-length
] } |
hostname host-name
}
key
[
cipher string
]
undo pre-shared-key
{
address
{
ipv4-address
[
mask
|
mask-length
] |
ipv6 ipv6-address
[
prefix-length
] } |
hostname host-name
}
Default
No pre-shared key is configured.
Views
IKE keychain view
Predefined user roles
network-admin
Summary of Contents for FlexNetwork MSR Series
Page 1005: ...987 ...