H3C Technologies H3C S5560 Series Switches User Manual
Page 426
data:image/s3,"s3://crabby-images/a16df/a16df71ce27c875143ab6398561e69c690759f5f" alt="background image"
410
# Configure the inbound and outbound SPIs for ESP.
[SwitchB-ipsec-profile-profile001-manual] sa spi inbound esp 200000
[SwitchB-ipsec-profile-profile001-manual] sa spi outbound esp 200000
# Configure the inbound and outbound SA keys for AH.
[SwitchB-ipsec-profile-profile001-manual] sa string-key inbound ah simple abc
[SwitchB-ipsec-profile-profile001-manual] sa string-key outbound ah simple abc
# Configure the inbound and outbound SA keys for ESP.
[SwitchB-ipsec-profile-profile001-manual] sa string-key inbound esp simple 123
[SwitchB-ipsec-profile-profile001-manual] sa string-key outbound esp simple 123
[SwitchB-ipsec-profile-profile001-manual] quit
# Create a manual IPsec profile named profile002.
[SwitchB] ipsec profile profile002 manual
# Reference IPsec transform set trans.
[SwitchB-ipsec-profile-profile002-manual] transform-set trans
# Configure the inbound and outbound SPIs for AH.
[SwitchB-ipsec-profile-profile002-manual] sa spi inbound ah 4294967295
[SwitchB-ipsec-profile-profile002-manual] sa spi outbound ah 4294967295
# Configure the inbound and outbound SPIs for ESP.
[SwitchB-ipsec-profile-profile002-manual] sa spi inbound esp 256
[SwitchB-ipsec-profile-profile002-manual] sa spi outbound esp 256
# Configure the inbound and outbound SA keys for AH.
[SwitchB-ipsec-profile-profile002-manual] sa string-key inbound ah simple hello
[SwitchB-ipsec-profile-profile002-manual] sa string-key outbound ah simple hello
# Configure the inbound and outbound SA keys for ESP.
[SwitchB-ipsec-profile-profile002-manual] sa string-key inbound esp simple byebye
[SwitchB-ipsec-profile-profile002-manual] sa string-key outbound esp simple
byebye
[SwitchB-ipsec-profile-profile002-manual] quit
{
On Switch C:
# Create an IPsec transform set named trans.
[SwitchC] ipsec transform-set trans
# Specify the encapsulation mode as transport.
[SwitchC-ipsec-transform-set-trans] encapsulation-mode transport
# Specify the ESP encryption and authentication algorithms.
[SwitchC-ipsec-transform-set-trans] esp encryption-algorithm 3des-cbc
# Specify the AH authentication algorithm.
[SwitchC-ipsec-transform-set-trans] esp authentication-algorithm md5
[SwitchC-ipsec-transform-set-trans] ah authentication-algorithm md5
[SwitchC-ipsec-transform-set-trans] quit
# Create a manual IPsec profile named profile002.
[SwitchC] ipsec profile profile002 manual
# Reference IPsec transform set trans.
[SwitchC-ipsec-profile-profile002-manual] transform-set trans
# Configure the inbound and outbound SPIs for AH.
[SwitchC-ipsec-profile-profile002-manual] sa spi inbound ah 4294967295