Chapter 23 • Practical IPv6 Security Solutions 431
authkey 1234567890abcdef1234567890abcdef encrkey 1234567890abcdef
add esp spi 0x5555 src ipv6s1.zama6.com dst sea-mach2.zama6.com auth_alg md5
encr_alg
des \
authkey 1234567890abcdef1234567890abcdef encrkey 1234567890abcdef
Let’s examine each line. The first line adds an SA for traffic headed for our
IPsec partner. Let’s look at each field in the first line—you can figure out
the second line.
add means we’re adding an SA.
esp specifies that this is an ESP SA, as opposed to an
authentication-and-integrity (AH) SA.
0x4444 is the “SPI,” which uniquely identifies this SA.
src sea-mach2.zama6.com specifies the source for this SA is
sea-mach2.
dst ipv6s1.zama6.com specifies the destination for this SA.
auth_alg md5 specifies ...