Displaying and maintaining IPsec
Execute display commands in any view and reset commands in user view.
Task
Display IPsec policy information.
Display IPsec policy template information.
Display IPsec profile information.
Display IPsec transform set information.
Display IPsec SA information.
Display IPsec statistics.
Display IPsec tunnel information.
Clear IPsec SAs.
Clear IPsec statistics.
IPsec configuration examples
Configuring a manual mode IPsec tunnel for IPv4 packets
Network requirements
As shown in
flows between the switches. Configure the tunnel as follows:
•
Specify the encapsulation mode as tunnel, the security protocol as ESP, the encryption
algorithm as AES-CBC-192, and the authentication algorithm as HMAC-SHA1.
•
Manually set up IPsec SAs.
Figure 86 Network diagram
Vlan-int1
2.2.2.1/24
Switch A
Configuration procedure
1.
Configure Switch A:
# Configure an IP address for VLAN-interface 1.
<SwitchA> system-view
[SwitchA] interface vlan-interface 1
Figure
86, establish an IPsec tunnel between Switch A and Switch B to protect data
Internet
Command
display ipsec { ipv6-policy | policy } [ policy-name
[ seq-number ] ]
display
ipsec
policy-template } [ template-name [ seq-number ] ]
display ipsec profile [ profile-name ]
display ipsec transform-set [ transform-set-name ]
display ipsec sa [ brief | count | interface interface-type
interface-number | { ipv6-policy | policy } policy-name
[ seq-number ] | profile policy-name | remote [ ipv6 ]
ip-address ]
display ipsec statistics [ tunnel-id tunnel-id ]
display ipsec tunnel { brief | count | tunnel-id
tunnel-id }
reset ipsec sa [ { ipv6-policy | policy } policy-name
[ seq-number ] | profile policy-name | remote
{ ipv4-address | ipv6 ipv6-address } | spi { ipv4-address |
ipv6 ipv6-address } { ah | esp } spi-num ]
reset ipsec statistics [ tunnel-id tunnel-id ]
Vlan-int1
2.2.3.1/24
Switch B
280
ipv6-policy-template
{
|
Need help?
Do you have a question about the FlexNetwork 5510 HI Series and is the answer not in the manual?