beautypg.com

H3C Technologies H3C SecPath F1000-E User Manual

Page 245

background image

233

Item

Description

Pre-Shared Key

Select the authentication method for IKE negotiation and specify the required
argument. Options include:

Pre-Shared Key—Uses the pre-shared key authentication method.

PKI Domain—Uses the RSA signature authentication method. Available PKI

domains are those configured by selecting VPN > Certificate Manager > Domain
from the navigation tree.

IMPORTANT:

If you select PKI Domain, an IKE proposal numbered 1 will be created.

PKI Domain

Enable DPD

Select this box to enable dead peer detection (DPD).

IMPORTANT:

If you enable DPD and the name of the IPsec VPN is abc, the wizard will create a DPD

named abc_dpd and apply it to peer abc_peer.

6.

Click Next.

Figure 145 IPsec VPN policy configuration wizard: 4/4 (peer node)

7.

Click Finish to complete the configuration.
The system jumps to the page that you can enter by selecting VPN > IPSec > IPSec Application from
the navigation tree.