Enabling Logging Of Ipsec Packets; Configuring The Df Bit Of Ipsec Packets - HPE FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Step
3.
Enable QoS pre-classify.

Enabling logging of IPsec packets

Perform this task to enable the logging of IPsec packets that are discarded because of reasons such
as IPsec SA lookup failure, AH-ESP authentication failure, and ESP encryption failure. The log
information includes the source and destination IP addresses, SPI value, and sequence number of a
discarded IPsec packet, and the reason for the discard.
To enable the logging of IPsec packets:
Step
1.
Enter system view.
2.
Enable the logging of IPsec
packets.

Configuring the DF bit of IPsec packets

Perform this task to configure the Don't Fragment (DF) bit in the new IP header of IPsec packets in
one of the following ways:
clear—Clears the DF bit in the new header.
set—Sets the DF bit in the new header.
copy—Copies the DF bit in the original IP header to the new IP header.
You can configure the DF bit in system view and interface view. The interface-view DF bit setting
takes precedence over the system-view DF bit setting. If the interface-view DF bit setting is not
configured, the interface uses the system-view DF bit setting.
Follow these guidelines when you configure the DF bit:
The DF bit setting takes effect only in tunnel mode, and it changes the DF bit in the new IP
header rather than the original IP header.
Configure the same DF bit setting on the interfaces where the same IPsec policy bound to a
source interface is applied.
If the DF bit is set, the devices on the path cannot fragment the IPsec packets. To prevent IPsec
packets from being discarded, make sure the path MTU is larger than the IPsec packet size. As
a best practice, clear the DF bit if you cannot make sure the path MTU is larger than the IPsec
packet size.
To configure the DF bit of IPsec packets on an interface:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Configure the DF bit of
IPsec packets on the
interface.
To configure the DF bit of IPsec packets globally:
Command
qos pre-classify
Command
system-view
ipsec logging packet enable
Command
system-view
interface interface-type
interface-number
ipsec df-bit { clear | copy | set }
348
Remarks
By default, QoS pre-classify is
disabled.
Remarks
N/A
By default, the logging of IPsec
packets is disabled.
Remarks
N/A
N/A
By default, the interface uses the
global DF bit setting.

Advertisement

Table of Contents
loading

Table of Contents