426
CN4093 Application Guide for N/OS 8.4
Using a Manual Key Policy
A
manual
policy
involves
configuring
policy
and
manual
SA
entries
for
local
and
remote
peers.
To
configure
a
manual
key
policy,
you
need:
The
IP
address
of
the
peer
in
IPv6
format
(for
example,
“3000::1”).
Inbound/Outbound
session
keys
for
the
security
protocols.
You
can
then
assign
the
policy
to
an
interface.
The
peer
represents
the
other
end
of
the
security
association.
The
security
protocol
for
the
session
key
can
be
either
ESP
or
AH.
To
create
and
configure
a
manual
policy:
1.
Enter
a
manual
policy
to
configure.
2.
Configure
the
policy.
where
the
following
parameters
are
used:
peer’s
IPv6
address
The
IPv6
address
of
the
peer
(for
example,
3000::1)
IPsec
traffic
‐
selector
A
number
from1
‐
10
IPsec
of
transform
‐
set
A
number
from1
‐
10
inbound
AH
IPsec
key
The
inbound
AH
key
code,
in
hexadecimal
inbound
AH
IPsec
SPI
A
number
from
256
‐
4294967295
inbound
ESP
cipher
key
The
inbound
ESP
key
code,
in
hexadecimal
inbound
ESP
SPI
A
number
from
256
‐
4294967295
inbound
ESP
authenticator
key
The
inbound
ESP
authenticator
key
code,
in
hexadecimal
outbound
AH
IPsec
key
The
outbound
AH
key
code,
in
hexadecimal
outbound
AH
IPsec
SPI
A
number
from
256
‐
4294967295
outbound
ESP
cipher
key
The
outbound
ESP
key
code,
in
hexadecimal
outbound
ESP
SPI
A
number
from
256
‐
4294967295
CN 4093(config)#
ipsec manual-policy
<policy
number>
CN 4093(config-ipsec-manual)#
peer
<peer’s
IPv6
address>
CN 4093(config-ipsec-manual)#
traffic-selector
<IPsec
traffic
selector>
CN 4093(config-ipsec-manual)#
transform-set
<IPsec
transform
set>
CN 4093(config-ipsec-manual)#
in-ah auth-key
<inbound
AH
IPsec
key>
CN 4093(config-ipsec-manual)#
in-ah auth-spi
<inbound
AH
IPsec
SPI>
CN 4093(config-ipsec-manual)#
in-esp cipher-key
<inbound
ESP
cipher
key>
CN 4093(config-ipsec-manual)#
in-esp auth-spi
<inbound
ESP
SPI>
CN 4093(config-ipsec-manual)#
in-esp auth-key
<inbound
ESP
authenticator
key>
CN 4093(config-ipsec-manual)#
out-ah auth-key
<outbound
AH
IPsec
key>
CN 4093(config-ipsec-manual)#
out-ah auth-spi
<outbound
AH
IPsec
SPI>
CN 4093(config-ipsec-manual)#
out-esp cipher-key
<outbound
ESP
cipher
key>
CN 4093(config-ipsec-manual)#
out-esp auth-spi
<outbound
ESP
SPI>
CN 4093(config-ipsec-manual)#
out-esp auth-key
<outbound
ESP
authenticator
key>
Summary of Contents for Flex System Fabric CN4093
Page 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Page 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Page 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Page 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Page 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Page 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Page 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Page 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Page 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Page 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Page 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Page 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Page 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Page 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Page 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Page 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Page 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Page 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Page 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Page 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Page 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Page 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Page 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Page 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Page 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Page 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Page 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Page 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Page 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Page 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Page 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Page 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Page 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Page 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Page 633: ......
Page 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...