Display Gdoi Gm Acl - HPE FlexNetwork HSR6800 Security Command Reference

Hide thumbs Also See for FlexNetwork HSR6800:
Table of Contents

Advertisement

Field
rule 0 deny udp source-port eq 848
destination-port eq 848
rule 1 deny ospf
rule 2 permit icmp
Rekey transport type
Lifetime (sec)
Encrypt algorithm
Key size
Sig hash algorithm
Sig key length (bit)
Interface
Transform
anti-replay window size(time based)
anti-replay window size(counter based)

display gdoi gm acl

Use display gdoi gm acl to display ACL information for GMs.
Syntax
display gdoi gm acl [ download | local ] [ group group-name ] [ | { begin | exclude | include }
regular-expression ]
Views
Any view
Default command level
1: Monitor level
Parameters
download: Displays the ACL information that the GM downloaded from the KS.
local: Displays the ACL information locally configured on the GM.
group group-name: Displays ACL information for GMs of a GDOI GM group. The group-name
argument is the GDOI GM group name, a case-sensitive string of 1 to 63 characters. If you do not
specify this option, the command displays ACL information for all GMs.
|: Filters command output by specifying a regular expression. For more information about regular
expressions, see Fundamentals Configuration Guide.
begin: Displays the first line that matches the specified regular expression and all lines that follow.
Description
Indicates that any UDP packets whose source and
destination port numbers are both 848 do not need to
be protected by IPsec.
Indicates that OSPF protocol packets do not need to be
protected by IPsec.
Indicates that any ICMP packets need to be protected
by IPsec.
Transport type of rekey messages: Multicast or Unicast.
KEK lifetime, in seconds.
KEK encryption algorithm.
KEK key length.
KEK signature hash algorithm.
KEK signature key length, in bits.
Name of the interface bound to the TEK.
Transform set.
Time-based anti-replay window size, in seconds.
This field is displayed only when anti-replay detection is
enabled.
Traffic-based anti-replay window size: 32, 64, 128, 256,
512, or 1024, in packets.
This field is displayed only when anti-replay detection is
enabled.
504

Advertisement

Table of Contents
loading

Table of Contents