Download Print this page

HP FlexNetwork MSR Series Command Reference Manual page 479

Comware 7 security
Hide thumbs Also See for FlexNetwork MSR Series:

Advertisement

Outbound AH setting:
AH SPI: 1237 (0x000004d5)
AH string-key: ******
AH authentication hex key:
Outbound ESP setting:
ESP SPI: 1238 (0x000004d6)
ESP string-key: ******
ESP encryption hex key:
ESP authentication hex key:
Table 66 Command output
Field
IPsec Policy
Interface
Sequence number
Mode
The policy configuration is incomplete
Description
Traffic Flow Confidentiality
Security data flow
Selector mode
Local address
Remote address
Transform set
IKE profile
IKEv2 profile
SA duration(time based)
SA duration(traffic based)
Description
IPsec policy name.
Interface applied with the IPsec policy.
Sequence number of the IPsec policy entry.
Negotiation mode of the IPsec policy:
Manual—Manual mode.
ISAKMP—IKE negotiation mode.
Template—IPsec policy template mode.
GDOI—GDOI mode.
IPsec policy configuration incomplete. Possible causes include:
The ACL is not configured.
The IPsec transform set is not configured.
The ACL does not have any permit statements.
The IPsec transform set configuration is not complete.
The peer IP address of the IPsec tunnel is not specified.
The SPI and key of the IPsec SA do not match those in the
IPsec policy.
Description of the IPsec policy.
Whether Traffic Flow Confidentiality (TFC) padding is enabled.
ACL used by the IPsec policy.
Data flow protection mode of the IPsec policy:
standard
aggregation
per-host
Local end IP address of the IPsec tunnel (available only for the
IKE-based IPsec policy).
Remote end IP address or host name of the IPsec tunnel.
Transform set used by the IPsec policy.
IKE profile used by the IPsec policy.
IKEv2 profile used by the IPsec policy.
Time-based IPsec SA lifetime, in seconds.
Traffic-based IPsec SA lifetime, in kilobytes.
461

Advertisement

loading