Configuring Snmp Notifications For Ike; Displaying And Maintaining Ike - HPE FlexFabric 5940 Series Security Configuration Manual

Hide thumbs Also See for FlexFabric 5940 Series:
Table of Contents

Advertisement

The supported maximum number of established IKE SAs depends on the device's memory
space. Adjust the maximum number of established IKE SAs to make full use of the device's
memory space without affecting other applications in the system.
To set the limit on the number of IKE SAs:
Step
1.
Enter system view.
2.
Set the maximum number of
half-open IKE SAs and the
maximum number of
established IKE SAs.

Configuring SNMP notifications for IKE

After you enable SNMP notifications for IKE, the IKE module notifies the NMS of important module
events. The notifications are sent to the device's SNMP module. You can configure the notification
transmission parameters for the SNMP module to specify how the SNMP module displays
notifications. For more information about SNMP notifications, see Network Management and
Monitoring Configuration Guide.
To generate and output SNMP notifications for a specific IKE failure or event type, perform the
following tasks:
1.
Enable SNMP notifications for IKE globally.
2.
Enable SNMP notifications for the failure or event type.
To configure SNMP notifications for IKE:
Step
1.
Enter system view
2.
Enable SNMP
notifications for IKE
globally.
3.
Enable SNMP
notifications for the
specified failure or
event types.

Displaying and maintaining IKE

Execute display commands in any view and reset commands in user view.
Task
Display configuration information about all IKE
proposals.
Display information about the current IKE SAs.
Command
system-view
ike limit { max-negotiating-sa
negotiation-limit | max-sa
sa-limit }
Command
system-view
snmp-agent trap enable ike global
snmp-agent trap enable ike
[ attr-not-support | auth-failure |
cert-type-unsupport | cert-unavailable |
decrypt-failure | encrypt-failure |
invalid-cert-auth | invalid-cookie |
invalid-id | invalid-proposal |
invalid-protocol | invalid-sign |
no-sa-failure | proposal-add |
proposal–delete | tunnel-start |
tunnel-stop | unsupport-exch-type ] *
Command
display ike proposal
display ike sa [ verbose [ connection-id
connection-id | remote-address [ ipv6 ]
336
Remarks
N/A
By default, there is no limit to the
maximum number of IKE SAs.
Remarks
N/A
By default, SNMP notifications
for IKE are enabled.
By default, SNMP notifications
for all failure and event types
are enabled.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents