Enabling Packet Information Pre-Extraction On The Ipsec Tunnel Interface; Applying A Qos Policy To An Ipsec Tunnel Interface - HP 6600 Security Configuration Manual

Table of Contents

Advertisement

Enabling packet information pre-extraction on the IPsec tunnel
interface
Because packets that an IPsec tunnel interface passes to a physical interface are encapsulated, the QoS
module cannot obtain the 5-tuple (source IP, destination IP, source port, destination port, and protocol) of
the original packets. To address this problem, enable packet information pre-extraction on the tunnel
interface.
With packet information pre-extraction enabled, an IPsec tunnel interface buffers the IP 5-tuple data in
the original packets, so that the corresponding physical interface can perform QoS processing such as
traffic classification, IP precedence setting, rate limit, and congestion avoidance.
To implement QoS for IPsec packets, however, you also need to apply a QoS policy to the physical
outbound interface. For more information about how to apply a QoS policy to a physical interface, see
ACL and QoS Configuration Guide.
IMPORTANT:
When the QoS policy applied to the physical outbound interface provides congestion management, IPsec
packets arriving at the destination may be out of order. This may cause IPsec out of order to be dropped
by the IPsec anti-replay function. For more information, see
To enable packet information pre-extraction on an IPsec tunnel interface:
Step
1.
Enter system view.
2.
Enter tunnel interface view.
3.
Enable packet information
pre-extraction.

Applying a QoS policy to an IPsec tunnel interface

The device allows you to apply a QoS policy to the IPsec tunnel interface. In this case, QoS is performed
before IPsec encapsulation, and the priority of a resulting packet is the same as that of the original packet.
In addition, the QoS congestion management is done to the packets before encapsulation, avoiding the
disorder of IPsec packets.
This method is much more explicit and flexible than the QoS implementation method of enabling packet
information pre-extraction on the IPsec tunnel interface, which requires applying a QoS policy to the
physical outbound interface.
To apply a QoS policy to an IPsec tunnel interface:
Step
1.
Enter system view.
2.
Enter tunnel interface
view.
Command
system-view
interface tunnel number
qos pre-classify
Command
system-view
interface tunnel number
274
"Configuring the IPsec anti-replay
Remarks
N/A
N/A
Disabled by default.
For more information about the
command, see ACL and QoS
Command Reference.
Remarks
N/A
N/A
function."

Advertisement

Table of Contents
loading

This manual is also suitable for:

Hsr6600

Table of Contents