HP-UX IPSec version A.02.01 manpages
i
ipsec_config_add(1M) ipsec_config_add(1M)
(HP-UX IPSec Software Required)
NAME
ipsec_config_add - add HP-UX IPSec configuration objects in the HP-UX IPSec configuration database
SYNOPSIS
ipsec_config add
object_type argument_list
DESCRIPTION
The
ipsec_config add
command configures objects in the database. The following
ipsec_config
add
commands are described in more detail in the Options and Operands section below.
add auth
Configure authenthication records, which specify IKE identities and preshared keys.
add bypass
Configure entries in the HP-UX IPSec bypass list.
add cert
Add a certificate for the local system to the HP-UX IPSec storage scheme.
add crl
Add a Certificate Revocation List (CRL) to the HP-UX IPSec storage scheme.
add_csr
Create a Certificate Signing Request (CSR) for the local system.
add gateway
Configure gateway IPsec policies for HP-UX Mobile IPv6 Home Agents.
add host
Configure host IPsec policies.
add ike Configure Internet Key Exchange (IKE) policies.
add startup
Specify general operating parameters, including the option to automatically start HP-UX
IPSec at system boot-up time.
add tunnel
Configure tunnel IPsec policies.
Options and Operands
IPSEC_CONFIG ADD AUTH COMMAND
Name
add auth
- configure authenthication records, which specify IKE identity and preshared keys
Synopsis
ipsec_config add auth auth_name [
-nocommit|
nc]
-rem[ote
] ip_address [/prefix][
-x
|exchange AM
|MM]
[
-ltype local_id_type
-lid
local_id ]
[
-rtype
remote_id_type
-rid remote_id]
[
-preshared
|psk preshared_key]
Description
Authentication records contain preshared key and IKE identification information. You must configure
authentication records in the following topologies:
• Topologies that use preshared keys for IKE authentication.
• Topologies that use Aggressive Mode for IKE Phase 1 negotiations.
• Topologies that use security certificates and RSA signatures (RSASIG) with multi-homed systems
(local or remote).
• Topologies that use security certificates and RSA signatures (RSASIG) with remote systems that
do not use IP addresses for IKE IDs. (HP-UX systems use IP addresses for IKE IDs by default.)
You do not have to configure authentication records in the following topologies:
• Topologies that use only manual keys.
• Topologies that use only security certificates and RSA signatures (RSASIG) for IKE authentica-
tion, and the local and remote systems are not multi-homed, use Main Mode, and use IPv4 or
IPv6 addresses for the IKE ID type.
8 Hewlett-Packard Company − 1 − HP-UX IPSec A.02.01