Figure 9 – H3C Technologies H3C SecPath F1000-E User Manual
Page 706
9
Figure 9 Add an IKE peer
describes the configuration items for creating an IKE peer.
Table 5 IKE peer configuration items
Item
Description
Peer Name
Type a name for the IKE peer.
IKE Negotiation Mode
Select the IKE negotiation mode in phase 1, which can be Main or Aggressive.
IMPORTANT:
z
If one end of an IPsec tunnel is configured to obtain an IP address
dynamically, the IKE negotiation mode must be Aggressive. In this case,
SAs can be established as long as the username and password are
correct.
z
The specified negotiated mode is used when the local peer is the
negotiation initiator. When acting as the responder, the negotiation mode
of the initiator is used.
Local ID Type
Select the local ID type in IKE negotiation phase 1
IP Address: Uses an IP address as the ID in IKE negotiation.
Gateway Name: Uses a gateway name as the ID in IKE negotiation.
IMPORTANT:
In main mode, only the ID type of IP address can be used in IKE negotiation
and SA establishment.