Ipsec Df-Bit - HPE FlexNetwork 10500 Series Security Command Reference

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Syntax
ipsec decrypt-check enable
undo ipsec decrypt-check enable
Default
ACL checking for de-encapsulated IPsec packets is enabled.
Views
System view
Predefined user roles
network-admin
mdc-admin
Usage guidelines
In tunnel mode, the IP packet encapsulated in an inbound IPsec packet might not be under the
protection of the ACL specified in the IPsec policy. After being de-encapsulated, such packets bring
threats to the network security. In this scenario, you can enable ACL checking for de-encapsulated
IPsec packets. All packets failing the checking are discarded, improving the network security.
Examples
# Enable ACL checking for de-encapsulated IPsec packets.
<Sysname> system-view
[Sysname] ipsec decrypt-check enable

ipsec df-bit

Use ipsec df-bit to configure the DF bit for the outer IP header of IPsec packets on an interface.
Use undo ipsec df-bit to restore the default.
Syntax
ipsec df-bit { clear | copy | set }
undo ipsec df-bit
Default
The DF bit is not configured for the outer IP header of IPsec packets on an interface. The global DF
bit setting is used.
Views
Interface view
Predefined user roles
network-admin
mdc-admin
Parameters
clear: Clears the DF bit in the outer IP header. IPsec packets can be fragmented.
copy: Copies the DF bit setting of the original IP header to the outer IP header.
set: Sets the DF bit in the outer IP header. IPsec packets cannot be fragmented.
471

Advertisement

Table of Contents
loading

Table of Contents