< Home

(Optional) Configuring Rate Limiting for IPSec Tunnels

Context

When multiple IPSec tunnels are established on the device (for example, a branch device), traffic conflict occurs if the data traffic is high. You can set the rate limit for each IPSec tunnel. Excess traffic is then discarded and traffic on each tunnel can be correctly transmitted.

When the headquarter establishes IPSec tunnels with multiple branches, traffic conflict occurs between one branch and other branches if the data traffic of the branch is high. You can set the rate limit for each IPSec tunnel. Excess traffic is then discarded and traffic on each tunnel can be correctly transmitted.

Procedure

  1. Run system-view

    The system view is displayed.

  2. Run ipsec profile profile-name

    An IPSec profile is created and the IPSec profile view is displayed.

  3. Run speed-limit { inbound | outbound } speed-limit [ policy-based | sa-based ]

    Rate limiting is configured for IPSec tunnels.

    If a local interface will receive high-volume traffic over an IPSec tunnel, configure inbound to limit the incoming traffic. If the local interface will send high-volume traffic over an IPSec tunnel, configure outbound to limit the outgoing traffic.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >