Enabling Ipsec Packet Fragmentation Before/After Encryption - HP 6600 Security Configuration Manual

Table of Contents

Advertisement

Step
1.
Enter system view.
2.
Enter IPsec policy view or
IPsec policy template view.
3.
Enable IPsec RRI.
4.
Change the preference of
the static routes created by
IPsec RRI.
5.
Set a tag for the static
routes created by IPsec RRI.
IPsec RRI can operate in both tunnel mode and transport mode.
When you change the route attributes, static IPsec RRI deletes all static routes it has created and creates
new static routes. In contrast, dynamic IPsec RRI applies the new attributes only to subsequent static routes.
It does not delete or modify static routes it has created.

Enabling IPsec packet fragmentation before/after encryption

When IPsec packet fragmentation before encryption is enabled, an IPsec-protected interface first
fragments and then encapsulates the packet if the packet size exceeds the interface MTU.
When IPsec packet fragmentation after encryption is enabled, an IPsec-protected interface first
encapsulates a packet, and then fragments the packet if the encapsulated packet size exceeds the
interface MTU.
On an interface applied with an IPsec GDOI policy, IPsec packet fragmentation before encryption must
be enabled. Otherwise, the remote interface cannot decrypt the packets whose size is larger than the
MTU of the remote interface. For more information about GDOI, see "Configuring group encrypted
transport VPN."
To enable IPsec packet fragmentation before or after encryption :
Step
1.
Enter system view.
Command
system-view
To enter IPsec policy view:
ipsec policy policy-name
seq-number [ isakmp | manual ]
To enter IPsec policy template view:
ipsec policy-template
template-name seq-number
reverse-route [ remote-peer ip-address
[ gateway | static ] | static ]
reverse-route preference
preference-value
reverse-route tag tag-value
Command
system-view
269
Remarks
N/A
Use either command.
Disabled by default.
To enable static IPsec RRI, specify
the static keyword. If the keyword
is not specified, dynamic IPsec RRI
is enabled.
Optional.
60 by default.
Optional.
0 by default.
Remarks
N/A

Advertisement

Table of Contents
loading

This manual is also suitable for:

Hsr6600

Table of Contents