Setting The Maximum Number Of Ike Sas; Configuring An Ike Ipv4 Address Pool - HPE FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

sending the data by using the IPsec SA that has the invalid SPI, and the receiving peer keeps
dropping the traffic.
The invalid SPI recovery feature enables the receiving peer to set up an IKE SA with the originator so
that an SPI invalid notification can be sent. Upon receiving the notification, the originating peer
deletes the IPsec SA that has the invalid SPI. If the originator has data to send, new SAs will be set
up.
Use caution when you enable the invalid SPI recovery feature because using this feature can result
in a DoS attack. Attackers can make a great number of invalid SPI notifications to the same peer.
To enable invalid SPI recovery:
Step
1.
Enter system view.
2.
Enable invalid SPI recovery.

Setting the maximum number of IKE SAs

You can set the maximum number of half-open IKE SAs and the maximum number of established
IKE SAs.
The supported maximum number of half-open IKE SAs depends on the device's processing
capability. Adjust the maximum number of half-open IKE SAs to make full use of the device's
processing capability without affecting the IKE SA negotiation efficiency.
The supported maximum number of established IKE SAs depends on the device's memory
space. Adjust the maximum number of established IKE SAs to make full use of the device's
memory space without affecting other applications in the system.
To set the limit on the number of IKE SAs:
Step
1.
Enter system view.
2.
Set the maximum number of
half-open IKE SAs and the
maximum number of
established IKE SAs.

Configuring an IKE IPv4 address pool

To perform centralized management on remote users, an IPsec gateway can use an IPv4 address
pool to assign private IPv4 addresses to remote users.
You must use an IKE IPv4 address pool together with AAA authorization by specifying the IKE IPv4
address pool as an AAA authorization attribute. For more information about AAA authorization, see
"Configuring
To configure an IKE IPv4 address pool:
Step
1.
Enter system view.
AAA."
Command
system-view
ike invalid-spi-recovery
enable
Command
system-view
ike limit { max-negotiating-sa
negotiation-limit | max-sa
sa-limit }
Command
system-view
367
Remarks
N/A
By default, the invalid SPI recovery
is disabled.
Remarks
N/A
By default, there is no limit to the
maximum number of IKE SAs.
Remarks
N/A

Advertisement

Table of Contents
loading

Table of Contents