Configuring spoke additional settings, Configuring hub advanced settings – H3C Technologies H3C Intelligent Management Center User Manual

Page 126

Advertising
background image

116

The parameters in the IKE proposal template are automatically filled in the IKE proposal

configuration page.

e.

Go to step 6.

5.

Import an IKE proposal that has been configured on a hub device in the current VPN domain:

a.

Click the import icon

next to the hub proposal number.

The Select IKE Proposals window appears. This window lists the IKE proposals configured on
the hub devices in the current domain, except those do not match the IKE Authentication

method set in "

Configuring default IPsec and IKE settings

."

b.

Enter the number of the IKE proposal you want to query, and click Query.

c.

Select the IKE proposal in the IKE Proposal List.

d.

Click OK.
The parameters in the IKE proposal are automatically filled in the IKE proposal configuration
page.

e.

Go to step 6.

6.

Click OK.
The IKE Authentication method is inherited from the VPN domain, and cannot be modified when
you configure the IKE proposal.

Configuring spoke additional settings

1.

Select the IP Address of the Spoke Interface option to configure the IP address of the spoke

interface:

a.

Enter the name of the spoke interface in the Interface Name box, such as Ethernet0/5 or

Loopback100.

b.

Enter the IP address of the spoke interface in the IP Address box.

c.

Enter the mask of the IP address in the Mask box.

2.

Select the DHCP Relay option to configure the DHCP relay function for the spoke:

a.

Enter the name of the DHCP relay interface in the box, such as Ethernet0/6.

b.

Enter the DHCP server group ID in the Server Group ID box, in the range of 1 to 20.

c.

Enter the IP address of the DHCP server in the Server IP Address box.
The spoke will forward received DHCP requests to the specified DHCP server.

3.

Select the User-Defined Settings option and add commands line by line in the box. For example:

ip route-static 100.1.1.1 24 Ethernet0/1 60.2.2.3 tag 20

ip route-static 100.2.2.1 24 Ethernet0/1 60.3.3.2 tag 30

4.

Click OK.

Configuring hub advanced settings

1.

Enter the name of the IPsec policy in the IPsec Policy Name box.

{

This setting corresponds to the following CLI command when the IPsec policy template is not
enabled:

ipsec policy policy-name seq-number isakmp

policy-name—Specifies the name of the IPsec policy.
seq-number—Specifies the sequence number, which is 1 if only one IPsec policy has the
specified name. If multiple IPsec policies have the same name, IVM numbers the policies in the

order they are configured, and the policies form an IPsec policy group.

Advertising