Configuring Packet Information Pre-Extraction; Enabling Invalid Spi Recovery - HP 12500 Series Configuration Manual

Routing
Table of Contents

Advertisement

IMPORTANT:
IPsec anti-replay checking is enabled by default. Do not disable it unless it needs to be disabled.
A wider anti-replay window results in higher resource cost and more system performance degradation,
which is against the original intention of the IPsec anti-replay function. Specify an anti-replay window
size that is as small as possible.
To configure IPsec anti-replay checking:
Step
1.
Enter system view.
2.
Enable IPsec anti-replay
checking.
3.
Set the size of the IPsec
anti-replay window.

Configuring packet information pre-extraction

If you apply both an IPsec policy and QoS policy to an interface, by default, the interface first uses IPsec
and then QoS to process IP packets, and QoS classifies packets by the headers of IPsec-encapsulated
packets. If you want QoS to classify packets by the headers of the original IP packets, enable the packet
information pre-extraction feature.
For more information about QoS policy and classification, see ACL and QoS Configuration Guide.
To configure packet information pre-extraction:
Step
1.
Enter system view.
2.
Enter IPsec policy view.
Enable packet information
3.
pre-extraction.

Enabling invalid SPI recovery

When the security gateway at one end of an IPsec tunnel loses its SAs due to rebooting or any other
reason, its peer security gateway may not know the problem and send IPsec packets to it. These packets
will be discarded by the receiver because the receiver cannot find appropriate SAs for them, resulting in
a traffic blackhole. This situation changes only after the concerned SAs on the sender get aged out and
Command
system-view
ipsec anti-replay check
ipsec anti-replay window width
Command
system-view
ipsec policy policy-name
seq-number [ isakmp | manual ]
qos pre-classify
180
Remarks
N/A
Optional.
Enabled by default.
This command is available only for
FIPS mode.
Optional.
32 by default.
This command is available only for
FIPS mode.
Remarks
N/A
This command is available only for
FIPS mode.
Disabled by default.
This command is available only for
FIPS mode.

Advertisement

Table of Contents
loading

Table of Contents