Setting The Maximum Number Of Ike Sas; Displaying And Maintaining Ike - H3C S5830V2 Security Configuration Manual

Hide thumbs Also See for S5830V2:
Table of Contents

Advertisement

which it cannot find an SA, an invalid SPI is encountered. The peer drops the data packet and tries to
send an SPI invalid notification to the data originator. This notification is sent by using the IKE SA.
Because no IKE SA is available, the notification is not sent. The originating peer continues sending the
data by using the IPsec SA that has the invalid SPI, and the receiving peer keeps dropping the traffic.
The invalid SPI recovery feature enables the receiving peer to set up an IKE SA with the originator so that
an SPI invalid notification can be sent. Upon receiving the notification, the originating peer deletes the
IPsec SA that has the invalid SPI. If the originator has data to send, new SAs will be set up.
Use caution when enabling the invalid SPI recovery feature because using this feature can result in a DoS
attack. Attackers can fabric a great number of invalid SPI notifications to the same peer.
To enable invalid SPI recovery:
Step
1.
Enter system view.
2.
Enable invalid SPI recovery.

Setting the maximum number of IKE SAs

You can set the maximum number of half-open IKE SAs and the maximum number of established IKE SAs.
The supported maximum number of half-open IKE SAs depends on the device's processing
capability. Adjust the maximum number of half-open IKE SAs to make full use of the device's
processing capability without affecting the IKE SA negotiation efficiency.
The supported maximum number of established IKE SAs depends on the device's memory space.
Adjust the maximum number of established IKE SAs to make full use of the device's memory space
without affecting other applications in the system.
To set the maximum number of IKE SAs:
Step
1.
Enter system view.
2.
Set the maximum number of
half-open IKE SAs and the
maximum number of
established IKE SAs.

Displaying and maintaining IKE

Execute display commands in any view and reset commands in user view.
Task
Display configuration information about all IKE
proposals.
Display information about the current IKE SAs.
Command
system-view
ike invalid-spi-recovery enable
Command
system-view
ike limit { max-negotiating-sa
negotiation-limit | max-sa
sa-limit }
Command
display ike proposal
display ike sa [ verbose [ connection-id connection-id
| remote-address [ ipv6 ] remote-address
[ vpn-instance vpn-name ] ] ]
274
Remarks
N/A
By default, the invalid SPI recovery
is disabled.
Remarks
N/A
By default, there is no limit to the
maximum number of IKE SAs.

Advertisement

Table of Contents
loading

This manual is also suitable for:

S5820v2

Table of Contents