HP 6125XLG R2306-HP 6125XLG Blade Switch Security Command Reference - Page 248

Table 35, Command output, Path MTU of the IPsec SA.

Page 248 highlights

Status: active Global IPsec SA IPsec profile: profile Mode: manual Encapsulation mode: transport [Inbound AH SAs] SPI: 1234563 (0x0012d683) Transform set: AH-SHA1 No duration limit for this SA [Outbound AH SAs] SPI: 1234563 (0x002d683) Transform set: AH-SHA1 No duration limit for this SA Table 35 Command output Field Interface IPsec policy IPsec profile Sequence number Mode Tunnel id Encapsulation mode Perfect Forward Secrecy Path MTU Tunnel local address remote address Flow Description Interface where the IPsec SA belongs. Name of the used IPsec policy. Name of the used IPsec profile. Sequence number of the IPsec policy entry. Negotiation mode used by the IPsec policy: • manual • isakmp IPsec tunnel ID Encapsulation mode, transport or tunnel. Perfect forward secrecy (PFS) used by the IPsec policy for negotiation: • 768-bit Diffie-Hellman group (dh-group1) • 1024-bit Diffie-Hellman group (dh-group2) • 1536-bit Diffie-Hellman group (dh-group5) • 2048-bit Diffie-Hellman group (dh-group14) • 2048-bit and 256_bit subgroup Diffie-Hellman group (dh-group24) Path MTU of the IPsec SA. Local and remote addresses of the IPsec tunnel. Local end IP address of the IPsec tunnel. Remote end IP address of the IPsec tunnel. Information about the data flow protected by the IPsec tunnel. 239

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321

239
Status: active
-------------------------------
Global IPsec SA
-------------------------------
-----------------------------
IPsec profile: profile
Mode: manual
-----------------------------
Encapsulation mode: transport
[Inbound AH SAs]
SPI: 1234563 (0x0012d683)
Transform set: AH-SHA1
No duration limit for this SA
[Outbound AH SAs]
SPI: 1234563 (0x002d683)
Transform set: AH-SHA1
No duration limit for this SA
Table 35
Command output
Field
Description
Interface
Interface where the IPsec SA belongs.
IPsec policy
Name of the used IPsec policy.
IPsec profile
Name of the used IPsec profile.
Sequence number
Sequence number of the IPsec policy entry.
Mode
Negotiation mode used by the IPsec policy:
manual
isakmp
Tunnel id
IPsec tunnel ID
Encapsulation mode
Encapsulation mode, transport or tunnel.
Perfect Forward Secrecy
Perfect forward secrecy (PFS) used by the IPsec policy for
negotiation:
768-bit Diffie-Hellman group (
dh-group1
)
1024-bit Diffie-Hellman group (
dh-group2
)
1536-bit Diffie-Hellman group (
dh-group5
)
2048-bit Diffie-Hellman group (
dh-group14
)
2048-bit and 256_bit subgroup Diffie-Hellman group
(
dh-group24
)
Path MTU
Path MTU of the IPsec SA.
Tunnel
Local and remote addresses of the IPsec tunnel.
local address
Local end IP address of the IPsec tunnel.
remote address
Remote end IP address of the IPsec tunnel.
Flow
Information about the data flow protected by the IPsec tunnel.