Protection modes, Configuring an ipsec proposal, Figure 9 – H3C Technologies H3C SecPath F1000-E User Manual
Page 721
9
Figure 9 Non-mirror image ACLs
Protection modes
Currently, data flows can be protected in two modes:
•
Standard mode: One tunnel is used to protect one data flow. That is, the data flow permitted by
each ACL rule is protected by one tunnel that is established separately for it.
•
Aggregation mode: One tunnel is used to protect all data flows permitted by all the rules of an ACL.
This mode applies to only scenarios using IKE for negotiation.
.
Configuring an IPsec Proposal
Select VPN > IPSec > Proposal from the navigation tree to enter the IPsec proposal management
page as shown in
. Then, click Add to enter the IPsec proposal configuration wizard page
shown in
Figure 10 IPsec proposal list
Figure 11 IPsec proposal configuration wizard page
The Web interface provides two modes for configuring an IPsec proposal: suite mode and custom mode.