Ipsec Logging Packet Enable - HP 5920 Command Reference Manual

Table of Contents

Advertisement

undo ipsec decrypt-check enable
Default
ACL checking for de-encapsulated IPsec packets is enabled.
Views
System view
Predefined user roles
network-admin
Usage guidelines
In tunnel mode, the IP packet encapsulated in an inbound IPsec packet might not be under the protection
of the ACL specified in the IPsec policy. After being de-encapsulated, such packets bring threats to the
network security. In this scenario, you can enable ACL checking for de-encapsulated IPsec packets. All
packets failing the checking are discarded, improving the network security.
Examples
# Enable ACL checking for de-encapsulated IPsec packets.
<Sysname> system-view
[Sysname] ipsec decrypt-check enable

ipsec logging packet enable

Use ipsec logging packet enable to enable logging for IPsec packets.
Use undo ipsec logging packet enable to disable logging for IPsec packets.
Syntax
ipsec logging packet enable
undo ipsec logging packet enable
Default
Logging for IPsec packets is disabled.
Views
System view
Predefined user roles
network-admin
Usage guidelines
After logging for IPsec packets is enabled, the device outputs a log when an IPsec packet is discarded
due to, for example, lack of inbound SA, AH/ESP authentication failure, or ESP encryption failure. A log
contains the source and destination IP addresses, SPI, and sequence number of the packet, and why it
was discarded.
Examples
# Enable logging for IPsec packets.
338

Advertisement

Table of Contents
loading

This manual is also suitable for:

59005920 series5900 series

Table of Contents