HP 6125XLG R2306-HP 6125XLG Blade Switch Security Command Reference - Page 275

reset ipsec sa

Page 275 highlights

# Change the IP address for the host test to 2.2.2.2. [Sysname] ip host test 2.2.2.2 In this case, you must reconfigure the remote host name for the IPsec policy policy1 so that the local end can obtain the latest IP address of the remote host. # Reconfigure the remote host name to test for the IPsec tunnel in the IPsec policy policy1. [Sysname] ipsec policy policy1 1 isakmp [Sysname -ipsec-policy-isakmp-policy1-1] remote-address test Examples # Specify the remote IP address 10.1.1.2 for the IPsec tunnel. system-view [Sysname] ipsec policy policy1 10 manual [Sysname-ipsec-policy-policy1-10] remote-address 10.1.1.2 Related commands • ip host (see Layer 3-IP Services Commands Reference) • local-address reset ipsec sa Use reset ipsec sa to clear IPsec SAs. Syntax reset ipsec sa [ { ipv6-policy | policy } policy-name [ seq-number ] | profile policy-name | remote { ipv4-address | ipv6 ipv6-address } | spi { ipv4-address | ipv6 ipv6-address } { ah | esp } spi-num ] Views User view Predefined user roles network-admin Parameters { ipv6-policy | policy } policy-name [ seq-number ]: Clears IPsec SAs for the specified IPsec policy. • ipv6-policy: Specifies an IPv6 IPsec policy. • policy: Specifies an IPv4 IPsec policy. • policy-name: Specifies the name of the IPsec policy, a case-sensitive string of 1 to 63 characters. • seq-number: Specifies the sequence number of an IPsec policy entry, in the range of 1 to 65535. If no seq-number is specified, all the entries in the IPsec policy are specified. profile profile-name: Clears IPsec SAs for the IPsec profile specified by its name, a case-sensitive string of 1 to 63 characters. remote: Clears IPsec SAs for the specified remote address. • ipv4-address: Specifies a remote IPv4 address. • ipv6 ipv6-address: Specifies a remote IPv6 address. spi { ipv4-address | ipv6 ipv6-address } { ah | esp } spi-num ]: Clears IPsec SAs for the specified SA triplet: the remote address, the security protocol, and the SPI. • ipv4-address: Specifies a remote IPv4 address. 266

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321

266
# Change the IP address for the host
test
to 2.2.2.2.
[Sysname] ip host test 2.2.2.2
In this case, you must reconfigure the remote host name for the IPsec policy
policy1
so that the local end
can obtain the latest IP address of the remote host.
# Reconfigure the remote host name to
test
for the IPsec tunnel in the IPsec policy
policy1
.
[Sysname] ipsec policy policy1 1 isakmp
[Sysname -ipsec-policy-isakmp-policy1-1] remote-address test
Examples
# Specify the remote IP address 10.1.1.2 for the IPsec tunnel.
<Sysname> system-view
[Sysname] ipsec policy policy1 10 manual
[Sysname-ipsec-policy-policy1-10] remote-address 10.1.1.2
Related commands
ip host
(see
Layer 3—IP Services Commands Reference
)
local-address
reset ipsec sa
Use
reset ipsec sa
to clear IPsec SAs.
Syntax
reset
ipsec
sa
[ {
ipv6-policy
|
policy
}
policy-name
[
seq-number
] |
profile
policy-name
|
remote
{
ipv4-address
|
ipv6
ipv6-address
} |
spi
{
ipv4-address
|
ipv6
ipv6-address
} {
ah
|
esp
}
spi-num
]
Views
User view
Predefined user roles
network-admin
Parameters
{
ipv6-policy
|
policy
}
policy-name
[
seq-number
]: Clears IPsec SAs for the specified IPsec policy.
ipv6-policy
: Specifies an IPv6 IPsec policy.
policy
: Specifies an IPv4 IPsec policy.
policy-name
: Specifies the name of the IPsec policy, a case-sensitive string of 1 to 63 characters.
seq-number
: Specifies the sequence number of an IPsec policy entry, in the range of 1 to 65535. If
no
seq-number
is specified, all the entries in the IPsec policy are specified.
profile
profile-name
: Clears IPsec SAs for the IPsec profile specified by its name, a case-sensitive string of
1 to 63 characters.
remote
: Clears IPsec SAs for the specified remote address.
ipv4-address
: Specifies a remote IPv4 address.
ipv6
ipv6-address
: Specifies a remote IPv6 address.
spi
{
ipv4-address
|
ipv6
ipv6-address
} {
ah
|
esp
}
spi-num
]: Clears IPsec SAs for the specified SA triplet:
the remote address, the security protocol, and the SPI.
ipv4-address
: Specifies a remote IPv4 address.