R3303-HP HSR6800 Routers MPLS Command Reference
347
Usage guidelines
If two PEs belong to the same AS and a backdoor link is present, a sham link can be established between
them.
No matter which of the simple and the MD5/HMAC-MD5 authentication is used, for security purposes,
all authentication keys, including keys configured in plain text, are saved in cipher text to the
configuration file.
This command can configure MD5 or simple authentication for a sham link, but not both. For MD5/
HMAC-MD5 authentication, you can configure multiple keys by executing this command multiple times,
but a key-id can correspond with only one key.
If you configure an authentication mode for a sham link, this mode is used no matter whether a mode is
configured for the OSPF area where the sham link resides.
If you do not configure an authentication mode for a sham link but configure one for the OSPF area
where the sham link resides, the mode for the OSPF area is used.
Examples
# Create a sham link with the source address of 1.1.1.1 and the destination address of 2.2.2.2.
<Sysname> system-view
[Sysname] ospf
[Sysname-ospf-1] area 0
[Sysname-ospf-1-area-0.0.0.0] sham-link 1.1.1.1 2.2.2.2
tnl-policy (VPN instance view/IPv4 VPN view)
Use tnl-policy to associate the current VPN instance with a tunneling policy.
Use undo tnl-policy to remove the association.
Syntax
tnl-policy tunnel-policy-name
undo tnl-policy
Views
VPN instance view, IPv4 VPN view
Default command level
2: System level
Parameters
tunnel-policy-name: Specifies the name of the tunneling policy for the VPN instance, a string of 1 to 19
characters.
Usage guidelines
If a VPN instance is not associated with any tunneling policy or the associated tunneling policy is not
configured, the VPN instance selects tunnels according to the default tunneling policy. The default
tunneling policy selects only one tunnel in this order: LSP tunnel, GRE tunnel, CR-LSP tunnel.
A tunneling policy specified in VPN instance view is applicable to both the IPv4 VPN and the IPv6 VPN.
A tunneling policy specified in IPv4 VPN view is applicable to only the IPv4 VPN.










