Configuring Snmp Notifications For Ipsec - HPE FlexNetwork 5510 HI Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 5510 HI Series:
Table of Contents

Advertisement

Step
6.
Configure keys for the
IPsec SA.

Configuring SNMP notifications for IPsec

After you enable SNMP notifications for IPsec, the IPsec module notifies the NMS of important
module events. The notifications are sent to the device's SNMP module. You can configure the
notification transmission parameters for the SNMP module to specify how the SNMP module
displays notifications. For more information about SNMP notifications, see Network Management
and Monitoring Configuration Guide.
To generate and output SNMP notifications for a specific IPsec failure or event type, perform the
following tasks:
1.
Enable SNMP notifications for IPsec globally.
2.
Enable SNMP notifications for the failure or event type.
To configure SNMP notifications for IPsec:
Step
1.
Enter system view
2.
Enable
notifications
globally.
3.
Enable
notifications
specified failure or event
types.
Command
Configure an authentication key
in hexadecimal format for AH:
sa
hex-key
{ inbound | outbound } ah
{ cipher | simple } key-value
Configure an authentication key
in character format for AH:
sa string-key { inbound |
outbound } ah { cipher |
simple } key-value
Configure a key in character
format
sa string-key { inbound |
outbound } esp [ cipher |
simple ] key-value
Configure an authentication key
in hexadecimal format for ESP:
sa
hex-key
{ inbound | outbound } esp
{ cipher | simple } key-value
Configure an encryption key in
hexadecimal format for ESP:
sa
{ inbound | outbound } esp
{ cipher | simple } key-value
Command
system-view
SNMP
snmp-agent trap
for
IPsec
global
snmp-agent trap
[ auth-failure | decrypt-failure |
SNMP
encrypt-failure | invalid-sa-failure |
for
the
no-sa-failure
policy-attach
policy-detach
tunnel-stop ] *
authentication
for
ESP:
authentication
hex-key
encryption
enable
ipsec
enable
ipsec
|
policy-add
|
policy-delete
|
tunnel-start
279
Remarks
By default, no keys are configured
for the IPsec SA.
Configure a key for the security
protocol (AH, ESP, or both) you
have specified.
If you configure a key in character
format
for
ESP,
automatically
generates
authentication
key
encryption key for ESP.
If you configure a key in both the
character
and
hexadecimal
formats, only the most recent
configuration takes effect.
Remarks
N/A
By default, SNMP notifications for
IPsec are disabled.
By default, SNMP notifications for
|
all failure and event types are
|
disabled.
|
the
device
an
and
an

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents