598Examples# Configure the local device to always obtain the identity information from the local certificate forsignature authentication. system-view[sysname] ike signature-identity from-certificateRelated commandslocal-identityike identityinside-vpnUse inside-vpn to specify an inside VPN instance.Use undo inside-vpn to restore the default.Syntaxinside-vpn vpn-instance vpn-instance-nameundo inside-vpnDefaultNo inside VPN instance is specified for an IKE profile. The device forwards protected data to theVPN instance where the interface that receives the data resides.ViewsIKE profile viewPredefined user rolesnetwork-adminParametersvpn-instance vpn-instance-name: Specifies the MPLS L3VPN instance to which the deviceforwards protected data. The vpn-instance-name argument represents the VPN instance name, acase-sensitive string of 1 to 31 characters.Usage guidelinesThis command determines where the device should forward received IPsec protected data. If youconfigure this command, the device looks for a route in the specified VPN to forward the data. If youdo not configure this command, the device looks for a route in the VPN instance where the receivinginterface resides to forward the data.Examples# Specify the inside VPN instance vpn1 for IKE profile prof1. system-view[Sysname] ike profile prof1[Sysname-ike-profile-prof1] inside-vpn vpn-instance vpn1keychainUse keychain to specify an IKE keychain for pre-shared key authentication.Use undo keychain to remove an IKE keychain.Syntaxkeychain keychain-name