Download Print this page

Tfc Enable - HP FlexNetwork MSR Series Command Reference Manual

Comware 7 security
Hide thumbs Also See for FlexNetwork MSR Series:

Advertisement

policy-delete: Specifies notifications about events of deleting IPsec policies.
policy-detach: Specifies notifications about events of removing IPsec policies from interfaces.
tunnel-start: Specifies notifications about events of creating IPsec tunnels.
tunnel-stop: Specifies notifications about events of deleting IPsec tunnels.
Usage guidelines
If you do not specify any keywords, this command enables or disables all SNMP notifications for
IPsec.
To generate and output SNMP notifications for a specific IPsec failure type or event type, perform the
following tasks:
1.
Enable SNMP notifications for IPsec globally.
2.
Enable SNMP notifications for the failure type or event type.
Examples
# Enable SNMP notifications for IPsec globally.
<Sysname> system-view
[Sysname] snmp-agent trap enable ipsec global
# Enable SNMP notifications for events of creating IPsec tunnels.
[Sysname] snmp-agent trap enable ipsec tunnel-start

tfc enable

Use tfc enable to enable Traffic Flow Confidentiality (TFC) padding.
Use undo tfc enable to disable the TFC padding feature.
Syntax
tfc enable
undo tfc enable
Default
TFC padding is disabled.
Views
IPsec policy view
IPsec policy template view
Predefined user roles
network-admin
Usage guidelines
The TFC padding feature can hide the length of the original packet, and might affect the packet
encapsulation and de-encapsulation performance. This feature takes effect on UDP packets
encapsulated by ESP in transport mode and on original IP packets encapsulated by ESP in tunnel
mode.
Examples
# Enable TFC padding for the IPsec policy policy1.
<Sysname> system-view
[Sysname] ipsec policy policy1 10 isakmp
[Sysname-ipsec-policy-isakmp-policy1-10] tfc enable
514

Advertisement

loading