Enabling Acl Checking For De-Encapsulated Packets - HP MSR Series Configuration Manual

Hpe flexnetwork msr router series
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

Step
3.
Apply an IPsec policy to the
interface.
4.
Specify a traffic processing
card or device for the
interface (distributed devices
in standalone
mode/centralized devices in
IRF mode).
5.
Specify a traffic processing
card for the interface
(distributed devices in IRF
mode).

Enabling ACL checking for de-encapsulated packets

This feature compares the de-encapsulated incoming IPsec packets against the ACL in the IPsec
policy and discards those that do not match the ACL. This feature can protect networks against
attacks using forged IPsec packets.
This feature applies only to tunnel-mode IPsec.
To enable ACL checking for de-encapsulated packets:
Step
1.
Enter system view.
Command
ipsec apply { policy |
ipv6-policy } policy-name
service slot slot-number
service chassis chassis-number
slot slot-number
Command
system-view
304
Remarks
By default, no IPsec policy is
applied to the interface.
You can apply only one IPsec
policy to an interface.
An IKE-based IPsec policy can be
applied to multiple interfaces, and
a manual IPsec policy can be
applied to only one interface.
By default, no traffic processing
card or device is specified.
It is required when the following
conditions are met:
An IKE-based IPsec policy is
applied to global logical
interfaces, such as VLAN
interfaces and tunnel
interfaces.
The IPsec anti-replay
function is globally enabled.
The traffic processing card or
device specified for a tunnel
interface must be the card or
device where the source interface
of the tunnel interface resides.
By default, no traffic processing
card is specified.
It is required when the following
conditions are met:
An IKE-based IPsec policy is
applied to global logical
interfaces, such as VLAN
interfaces and tunnel
interfaces.
The IPsec anti-replay
function is globally enabled.
The traffic processing card
specified for a tunnel interface
must be the card where the
source interface of the tunnel
interface resides.
Remarks
N/A

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents