F3726, F3211, F3174, R5135, R3816-HP Firewalls and UTM Devices VPN Command Reference-6PW100

87
After you create an IPsec policy by referencing an IPsec policy template, to modify the configuration for
the IPsec policy, you must enter the IPsec policy template view instead of the IPsec policy view.
You cannot change the negotiation mode of an IPsec policy. To do so, you must delete the IPsec policy
and then re-create it.
Related commands
ipsec policy (system view)
ipsec policy-template
Examples
# Create an IPsec policy with the name policy2 and sequence number 200 by referencing IPsec policy
template temp1.
<Sysname> system-view
[Sysname] ipsec policy policy2 200 isakmp template temp1
ipsec policy-template
Use ipsec policy-template to create an IPsec policy template and enter the IPsec policy template view.
Use undo ipsec policy-template to delete the specified IPsec policy templates.
Syntax
ipsec policy-template template-name seq-number
undo ipsec policy-template template-name [ seq-number ]
Default
No IPsec policy template exists.
Views
System view
Default command level
2: System level
Parameters
template-name: Name for the IPsec policy template, a case-insensitive string of 1 to 41 characters. No
hyphen (-) can be included.
seq-number: Sequence number for the IPsec policy template, in the range 1 to 65535.
Usage guidelines
Using the undo command without the seq-number argument deletes an IPsec policy template group.
In an IPsec policy template group, an IPsec policy template with a smaller sequence number has a higher
priority.
Examples
# Create an IPsec policy template with the name template1 and the sequence number 100.
<Sysname> system-view
[Sysname] ipsec policy-template template1 100
[Sysname-ipsec-policy-template-template1-100]