HP VPN Firewall Appliances VPN Command Reference

81
ipsec policy isakmp template
Use ipsec policy isakmp template to create an IPsec policy by referencing an existing IPsec policy
template, so that IKE can use the IPsec policy for SA negotiation.
Use undo ipsec policy with the seq-number argument to delete an IPsec policy.
Use undo ipsec policy without the seq-number argument to delete an IPsec policy group.
Syntax
ipsec policy policy-name seq-number isakmp template template-name
undo ipsec policy policy-name [ seq-number ]
Views
System view
Default command level
2: System level
Parameters
policy-name: Specifies the name for the IPsec policy, a case-insensitive string of 1 to 15 characters. No
hyphen (-) can be included.
seq-number: Specifies the sequence number for the IPsec policy, in the range of 1 to 65535.
isakmp template template-name: Specifies the name of the IPsec policy template to be referenced.
Usage guidelines
In an IPsec policy group, an IPsec policy with a smaller sequence number has a higher priority.
After you create an IPsec policy by referencing an IPsec policy template, to modify the configuration for
the IPsec policy, you must enter the IPsec policy template view instead of the IPsec policy view.
You cannot change the negotiation mode of an IPsec policy. To do so, you must delete the IPsec policy
and then re-create it.
Related commands
ipsec policy (system view)
ipsec policy-template
Examples
# Create an IPsec policy with the name policy2 and sequence number 200 by referencing IPsec policy
template temp1.
<Sysname> system-view
[Sysname] ipsec policy policy2 200 isakmp template temp1
ipsec policy-template
Use ipsec policy-template to create an IPsec policy template and enter the IPsec policy template view.
Use undo ipsec policy-template to delete the specified IPsec policy templates.
Syntax
ipsec policy-template template-name seq-number