R2511-HP MSR Router Series Security Command Reference(V5)

586
group
Use group to specify the GDOI GM group to be referenced by the GDOI IPsec policy.
Use undo group to remove the GDOI GM group referenced by the GDOI IPsec policy.
Syntax
group group-name
undo group
Default
A GDOI IPsec policy does not reference any GDOI GM group.
Views
GDOI IPsec policy entry view
Default command level
2: System level
Parameters
group-name: Specifies the name of a GDOI GM group, a case-sensitive string of 1 to 63 characters. The
group must have existed.
Usage guidelines
A GDOI IPsec policy can reference only one GDOI GM group. If you configure this command for
multiple times, the last configuration takes effect.
GDOI IPsec policy entries of different GDOI IPsec policies can reference the same GDOI GM group, but
those of the same GDOI IPsec policy cannot.
Examples
# Configure a GDOI IPsec policy entry and enter its view. The IPsec policy name is map and the entry
sequence number is 1.
<Sysname> system-view
[Sysname] ipsec policy map 1 gdoi
# Reference GDOI GM group abc for the GDOI IPsec policy entry.
[Sysname-ipsec-policy-gdoi-map-1] group abc
Related commands
gdoi gm group
identity
Use identity to configure an ID for the GDOI GM group.
Use undo identity to delete the GDOI GM group ID.
Syntax
identity { address ip-address | number number }
undo identity
Default
No ID is configured for a GDOI GM group.