Enabling Qos Pre-Classify; Enabling Logging Of Ipsec Packets; Configuring The Df Bit Of Ipsec Packets - HPE FlexFabric 7900 Series Security Configuration Manual

Hide thumbs Also See for FlexFabric 7900 Series:
Table of Contents

Advertisement

Step
2.
Bind a source interface to an
IPsec policy.

Enabling QoS pre-classify

If you apply both an IPsec policy and a QoS policy to an interface, QoS classifies packets by using
the new headers added by IPsec. If you want QoS to classify packets by using the headers of the
original IP packets, enable the QoS pre-classify feature.
For more information about QoS policy and classification, see ACL and QoS Configuration Guide.
To enable the QoS pre-classify feature:
Step
1.
Enter system view.
2.
Enter IPsec policy view or
IPsec policy template view.
3.
Enable QoS pre-classify.

Enabling logging of IPsec packets

Perform this task to enable the logging of IPsec packets that are discarded because of reasons such
as IPsec SA lookup failure, AH-ESP authentication failure, and ESP encryption failure. The log
information includes the source and destination IP addresses, the SPI value, and the sequence
number of a discarded IPsec packet, and the reason for the failure.
To enable the logging of IPsec packets:
Step
1.
Enter system view.
2.
Enable the logging of IPsec
packets.

Configuring the DF bit of IPsec packets

Perform this task to configure the Don't Fragment (DF) bit in the new IP header of IPsec packets in
one of the following ways:
clear—Clears the DF bit in the new header.
set—Sets the DF bit in the new header.
copy—Copies the DF bit in the original IP header to the new IP header.
Command
ipsec { ipv6-policy | policy }
policy-name local-address
interface-type interface-number
Command
system-view
To enter IPsec policy view:
ipsec { policy | ipv6-policy }
policy-name seq-number
[ isakmp | manual ]
To enter IPsec policy
template view:
ipsec { policy-template |
ipv6-policy-template }
template-name seq-number
qos pre-classify
Command
system-view
ipsec logging packet enable
126
Remarks
By default, no source interface is
bound to an IPsec policy.
Remarks
N/A
N/A
By default, QoS pre-classify is
disabled.
Remarks
N/A
By default, the logging of IPsec
packets is disabled.

Advertisement

Table of Contents
loading

Table of Contents