Reset Ipsec Sa - HPE FlexNetwork HSR6800 Security Command Reference

Hide thumbs Also See for FlexNetwork HSR6800:
Table of Contents

Advertisement

reset ipsec sa

Use reset ipsec sa to clear IPsec SAs.
Syntax
reset ipsec sa [ parameters [ ipv6 ] dest-address protocol spi | policy policy-name [ seq-number ] |
remote [ ipv6 ] ip-address ]
Views
User view
Default command level
2: System level
Parameters
parameters: Specifies IPsec SAs that use the specified destination address, security protocol, and
SPI.
ipv6: Specifies an IPv6 address.
dest-address: Specifies the destination address, in dotted decimal notation.
protocol: Specifies the security protocol, which can be keyword ah or esp, case insensitive.
spi: Specifies the security parameter index in the range of 256 to 4294967295.
policy: Specifies IPsec SAs that use an IPsec policy or IPsec profile.
policy-name: Specifies the name of the IPsec policy or IPsec profile, a case-sensitive string of 1 to 15
alphanumeric characters.
seq-number: Specifies the sequence number of the IPsec policy, in the range of 1 to 65535. If no
seq-number is specified, all the policies in the IPsec policy group named policy-name are specified.
remote: Specifies SAs to or from a remote address, in dotted decimal notation.
ip-address: Specifies the remote IP address.
Usage guidelines
Immediately after a manually set up SA is cleared, the system automatically sets up a new SA based
on the parameters of the IPsec policy. After IKE negotiated SAs are cleared, the system sets up new
SAs only when IKE negotiation is triggered by interesting packets.
IPsec SAs appear in pairs. If you specify the parameters keyword to clear an IPsec SA, the IPsec
SA in the other direction is also automatically cleared.
If you do not specify any parameter, the command clears all IPsec SAs.
Examples
# Clear all IPsec SAs.
<Sysname> reset ipsec sa
# Clear the IPsec SA with a remote IP address of 10.1.1.2.
<Sysname> reset ipsec sa remote 10.1.1.2
# Clear all IPsec SAs of IPsec policy template policy1.
<Sysname> reset ipsec sa policy policy1
# Clear the IPsec SA of the IPsec policy with the name of policy1 and sequence number of 10.
<Sysname> reset ipsec sa policy policy1 10
# Clear the IPsec SA with a remote IP address of 10.1.1.2, security protocol of AH, and SPI of 10000.
<Sysname> reset ipsec sa parameters 10.1.1.2 ah 10000
286

Advertisement

Table of Contents
loading

Table of Contents