269
To apply a QoS policy to an IPsec tunnel interface:
To do…
Command…
Remarks
1.
Enter system view.
system-view
—
2.
Enter tunnel interface view.
interface tunnel
number
—
3.
Apply a QoS policy to the IPsec
tunnel interface.
qos apply policy
policy-name
{
inbound
|
outbound
}
Required.
For more information, see
ACL and
QoS Command Reference
.
Configuring IPsec for IPv6 routing protocols
This is the generic configuration procedure for configuring IPsec for IPv6 routing protocols:
1.
Configure an IPsec proposal to specify the security protocols, authentication and encryption
algorithms, and encapsulation mode.
2.
Configure a manual IPsec policy to specify the keys and SPI.
3.
Apply the IPsec policy to an IPv6 routing protocol.
Complete the following tasks to configure IPsec for IPv6 routing protocols:
Task Remarks
Required.
Configuring a manual IPsec policy
Required.
ACLs and IPsec tunnel addresses are not needed.
Applying an IPsec policy to an IPv6 routing
protocol
Required.
See
Layer 3
—
IP Routing Configuration Guide
.
Displaying and maintaining IPsec
To do…
Command…
Remarks
Display IPsec policy
information
display
ipsec
policy
[
brief
|
name
policy-name
[
seq-number
] ] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Display IPsec policy
template information
display
ipsec
policy-template
[
brief
|
name
template-name
[
seq-number
] ] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Display the configuration
of IPsec profiles
display ipsec profile
[
name
profile-name
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Display IPsec proposal
information
display
ipsec
proposal
[
proposal-name
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Display IPsec SA
information
display
ipsec
sa
[
brief
|
policy
policy-name
[
seq-number
] |
remote
ip-address
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Display IPsec packet
statistics
display
ipsec
statistics
[
tunnel-id
integer
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view