No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

Command Reference

AR500, AR510, and AR530 V200R007

This document describes all the configuration commands of the device, including the command function, syntax, parameters, views, default level, usage guidelines, examples, and related commands.
Rate and give feedback :
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
ike remote-address

ike remote-address

Function

The ike remote-address command configures a VPN instance that IPSec tunnel traffic belongs to according to the remote IP address of an IKE peer.

The undo ike remote-address command deletes a VPN instance that IPSec tunnel traffic belongs to according to the remote IP address of an IKE peer.

By default, a VPN instance that IPSec tunnel traffic belongs to is not configured on an IKE peer.

NOTE:

Only the AR509GW-L-D-H, AR503GW-LM7, AR503GW-LcM7, and AR509G-L-D-H support this command.

Format

ike remote-address remote-ip-address vpn-instance vpn-instance-name

undo ike remote-address remote-ip-address vpn-instance

Parameters

Parameter

Description

Value

remote-ip-address

Specifies the remote IP address of an IKE peer.

The value is in dotted decimal notation.

vpn-instance vpn-instance-name

Specifies the name of the VPN instance that IPSec tunnel traffic belongs to.

The VPN instance name must have been created.

Views

System view

Default Level

2: Configuration level

Usage Guidelines

Usage Scenario

During IPSec SA negotiation, if the IPSec policy template and ike remote-address are configured in the headquarters, you can run this command to configure a VPN instance that IPSec tunnel traffic belongs to according to the remote IP address of an IKE peer, thereby isolating traffic of different branches.

Prerequisites

The VPN instance has been created using the ip vpn-instance command and the route distinguisher (RD) has been configured for the VPN instance using the route-distinguisher command.

Precautions

  • When the ike remote-address command is used, the local-id-type command must be used to configure the IP address of the remote end as the remote ID.

Example

# Configure the VPN instance vpn1 for IPSec tunnel traffic of the IKE peer with the remote IP address of 10.1.1.1.

<Huawei> system-view
[Huawei] ip vpn-instance vpna
[Huawei-vpn-instance-vpna] ipv4-family
[Huawei-vpn-instance-vpna-af-ipv4] route-distinguisher 100:1
[Huawei-vpn-instance-vpna-af-ipv4] quit
[Huawei-vpn-instance-vpna] quit
[Huawei] ike remote-address 10.1.1.1 vpn-instance vpn1
Translation
Download
Updated: 2019-02-18

Document ID: EDOC1000097293

Views: 35335

Downloads: 101

Average rating:
This Document Applies to these Products
Related Documents
Related Version
Share
Previous Next