Ima Troubleshooting - GE MDS ORBIT MCR Technical Manual

Multiservice/edge connect routers
Table of Contents

Advertisement

Once it is determined through event logs that the configuration was changed by authorized user, the
current configuration hash can be loaded in the IMA and then MCR can be instructed to re-attest with
IMA server, as shown below.
> request service-vpn-ipsec-attest-with-ima conn-name IMA-CONN-1
The IMA status can then be checked again periodically for new attestation result:
> show services vpn
services vpn ipsec ipsec-status connections connection IMA
state
disconnected
failure-reason
last-timestamp
ima-evaluation
ima-recommendation "Access Allowed"

7.4 IMA Troubleshooting

Follow the troubleshooting steps described in VPN section on troubleshooting IMA connection failure.
Note that an IMA connection failure means that unit was unable to communicate or attest with IMA. It
does not mean there was an IMA evaluation failure.
410
none
2013-01-18T22:19:02+00:00
compliant
MDS Orbit MCR/ECR Technical Manual
MDS 05-6632A01, Rev. F

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mds orbit ecr

Table of Contents