R211x-HP Flexfabric 11900 Security Command Reference

Table Of Contents
193
Default
An IPsec policy does not reference any IKE profile, and the device selects an IKE profile configured in
system view for negotiation. If no IKE profile is configured, the globally configured IKE settings are used.
Views
IPsec policy view
Predefined user roles
network-admin
mdc-admin
Parameters
profile-name: Specifies an IKE profile by its name, a case-insensitive string of 1 to 63 characters.
Usage guidelines
The IKE profile referenced by an IPsec policy defines the parameters used for IKE negotiation.
An IPsec policy can reference only one IKE profile and they cannot reference any IKE profile that is
already referenced by another IPsec policy.
Examples
# Specify IPsec policy policy1 to reference IKE profile profile1.
<Sysname> system-view
[Sysname] ipsec policy policy1 10 isakmp
[Sysname-ipsec-policy-isakmp-policy1-10] ike-profile profile1
Related commands
ike profile
ipsec anti-replay check
Use ipsec anti-replay check to enable IPsec anti-replay checking.
Use undo ipsec anti-replay check to disable IPsec anti-replay checking.
Syntax
ipsec anti-replay check
undo ipsec anti-replay check
Default
IPsec anti-replay checking is enabled.
Views
System view
Predefined user roles
network-admin
mdc-admin
Usage guidelines
IPsec packet de-encapsulation involves complicated calculation. De-encapsulation of replayed packets is
not necessary but consumes large amounts of resources and degrades performance, resulting in DoS.