beautypg.com

Protection modes, Configuring an ipsec proposal, Figure 9 – H3C Technologies H3C SecPath F1000-E User Manual

Page 721

background image

9

Figure 9 Non-mirror image ACLs

Protection modes

Currently, data flows can be protected in two modes:

Standard mode: One tunnel is used to protect one data flow. That is, the data flow permitted by
each ACL rule is protected by one tunnel that is established separately for it.

Aggregation mode: One tunnel is used to protect all data flows permitted by all the rules of an ACL.
This mode applies to only scenarios using IKE for negotiation.

Return to

IPsec configuration task list

.

Configuring an IPsec Proposal

Select VPN > IPSec > Proposal from the navigation tree to enter the IPsec proposal management
page as shown in

Figure 10

. Then, click Add to enter the IPsec proposal configuration wizard page

shown in

Figure 11

.

Figure 10 IPsec proposal list

Figure 11 IPsec proposal configuration wizard page


The Web interface provides two modes for configuring an IPsec proposal: suite mode and custom mode.

This manual is related to the following products: