HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 224

Displaying and maintaining IPsec

Page 224 highlights

Step 1. Enter system view. Command system-view Remarks N/A 2. Enter interface view. interface interface-type interface-number N/A 3. Configure the DF bit of IPsec packets on the interface. ipsec df-bit { clear | copy | set } By default, the interface uses the global DF bit setting. To configure the DF bit of IPsec packets globally: Step 1. Enter system view. 2. Configure the DF bit of IPsec packets globally. Command Remarks system-view N/A By default, IPsec copies the DF bit ipsec global-df-bit { clear | copy | set } in the original IP header to the new IP header. Displaying and maintaining IPsec Execute display commands in any view and reset commands in user view. Task Display IPsec policy information. Display IPsec policy template information. Display IPsec profile information. Display IPsec transform set information. Display IPsec SA information. Display IPsec statistics. Display IPsec tunnel information. Clear IPsec SAs. Clear IPsec statistics. Command display ipsec { ipv6-policy | policy } [ policy-name [ seq-number ] ] display ipsec { ipv6-policy-template | policy-template } [ template-name [ seq-number ] ] display ipsec profile [ profile-name ] display ipsec transform-set [ transform-set-name ] display ipsec sa [ brief | count | interface interface-type interface-number | { ipv6-policy | policy } policy-name [ seq-number ] | profile policy-name | remote [ ipv6 ] ip-address ] display ipsec statistics [ tunnel-id tunnel-id ] display ipsec tunnel { brief | count | tunnel-id tunnel-id } reset ipsec sa [ { ipv6-policy | policy } policy-name [ seq-number ] | profile policy-name | remote { ipv4-address | ipv6 ipv6-address } | spi { ipv4-address | ipv6 ipv6-address } { ah | esp } spi-num ] reset ipsec statistics [ tunnel-id tunnel-id ] 215

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

215
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface
interface-type
interface-number
N/A
3.
Configure the DF bit of
IPsec packets on the
interface.
ipsec df-bit
{
clear
|
copy
|
set
}
By default, the interface uses the
global DF bit setting.
To configure the DF bit of IPsec packets globally:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Configure the DF bit of
IPsec packets globally.
ipsec global-df-bit
{
clear
|
copy
|
set
}
By default, IPsec copies the DF bit
in the original IP header to the
new IP header.
Displaying and maintaining IPsec
Execute
display
commands in any view and
reset
commands in user view.
Task
Command
Display IPsec policy information.
display
ipsec
{
ipv6-policy
|
policy
} [
policy-name
[
seq-number
] ]
Display IPsec policy template information.
display
ipsec
{
ipv6-policy-template
|
policy-template
}
[
template-name
[
seq-number
] ]
Display IPsec profile information.
display ipsec profile
[
profile-name
]
Display IPsec transform set information.
display ipsec transform-set
[
transform-set-name
]
Display IPsec SA information.
display
ipsec
sa
[
brief
|
count
|
interface
interface-type
interface-number
| {
ipv6-policy
|
policy
}
policy-name
[
seq-number
] |
profile
policy-name
|
remote
[
ipv6
]
ip-address
]
Display IPsec statistics.
display ipsec statistics
[
tunnel-id
tunnel-id
]
Display IPsec tunnel information.
display ipsec tunnel
{
brief
|
count
|
tunnel-id
tunnel-id
}
Clear IPsec SAs.
reset
ipsec
sa
[ {
ipv6-policy
|
policy
}
policy-name
[
seq-number
] |
profile
policy-name
|
remote
{
ipv4-address
|
ipv6
ipv6-address
}
|
spi
{
ipv4-address
|
ipv6
ipv6-address
} {
ah
|
esp
}
spi-num
]
Clear IPsec statistics.
reset ipsec statistics
[
tunnel-id
tunnel-id
]