587
The NAT keepalive interval must be shorter than the NAT session lifetime.
Examples
# Create an IKEv2 profile named
profile1
.
<Sysname> system-view
[Sysname] ikev2 profile profile1
# Set the NAT keepalive interval to 1200 seconds.
[Sysname-ikev2-profile-profile1]nat-keepalive 1200
Related commands
display ikev2 profile
ikev2 nat-keepalive
peer
Use
peer
to create an IKEv2 peer and enter its view, or enter the view of an existing IKEv2 peer.
Use
undo peer
to delete an IKEv2 peer.
Syntax
peer
name
undo peer
name
Default
No IKEv2 peers exist.
Views
IKEv2 keychain view
Predefined user roles
network-admin
Parameters
name
: Specifies a name for the IKEv2 peer. The peer name is a case-insensitive string of 1 to 63
characters.
Usage guidelines
An IKEv2 peer contains a pre-shared key and the criteria for looking up the peer. The criteria for peer
lookup includes the peer's host name, IP address, IP address range, and ID. The IKEv2 negotiation
initiator uses the peer's host name, IP address, or IP address range to look up its peer. The
responder uses the peer's IP address, IP address range, or ID to look up its peer.
Examples
# Create an IKEv2 keychain named
key1
and enter IKEv2 keychain view.
<Sysname> system-view
[Sysname] ikev2 keychain key1
# Create an IKEv2 peer named
peer1
.
[Sysname-ikev2-keychain-key1] peer peer1
Related commands
address
hostname
identity
Summary of Contents for FlexNetwork MSR Series
Page 1005: ...987 ...