Command Reference Guide

262sa authentication-hex 3Com Router 5000 Family and Router 6000 Family
Command Reference
View This command can be used in the following views:
Manually-Established IPSec Policy view
Description This command is only used for the ipsec policy in manual mode.
For the ipsec policy in isakmp mode, it is unnecessary to set the SA parameter
manually. IKE will automatically negotiate the SA parameter and establish a SA.
When configuring the SA of manual mode, the SA parameters of inbound and
outbound directions must be set separately.
The SA parameters set at both ends of the security tunnel must be fully matching. The
SPI and key for the SA input at the local end must be the same as those output at the
remote. The SA SPI and key output at the local end must be the same as those input
at the remote.
There are two ways of inputting a key: hex and character string. To input a character
string for a key, you must use the
sa string-key command. If two keys, input in
different ways, are available, the one specified the last takes effect. At both ends of a
security tunnel, the key should be input in the same way. If the key is input in
character string at one end, and it is input in hex at the other end, then a security
tunnel cannot be set up correctly.
Related Commands ipsec policy (Interface view)
ipsec policy (System view)
proposal
sa duration
security acl
tunnel local
tunnel remote