Configuring Ipsec Anti-Replay Redundancy - HP FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

IMPORTANT:
• IPsec anti-replay is enabled by default. Failure to detect anti-replay attacks might result in denial
of services. Use caution when you disable IPsec anti-replay.
• Specify an anti-replay window size that is as small as possible to reduce the impact on system
performance.
• Typically, the device processes packets for a global logical interface (such as a VLAN interface)
directly on the cards that received the packets. However, IPsec anti-replay requires that packets
sent and received on the same global logical interface be processed by the same card. To
implement IPsec anti-replay on the device, use the service command in the global logical
interface view to specify a card for forwarding the traffic on the interface.
To configure IPsec anti-replay:
Step
1.
Enter system view.
2.
Enable IPsec anti-replay.
3.
Set the size of the IPsec
anti-replay window.

Configuring IPsec anti-replay redundancy

This feature synchronizes the following information from the active device to the standby device at
configurable packet-based intervals:
Lower bound values of the IPsec anti-replay window for inbound packets.
IPsec anti-replay sequence numbers for outbound packets.
This feature, used together with IPsec redundancy, ensures uninterrupted IPsec traffic forwarding
and anti-replay protection when the active device fails.
To configure IPsec anti-replay redundancy:
Step
1.
Enter system view.
2.
Enable IPsec redundancy.
3.
Enter IPsec policy view or
IPsec policy template view.
4.
Set the anti-replay window
synchronization interval for
inbound packets and the
sequence number
synchronization interval for
outbound packets.
Command
system-view
ipsec anti-replay check
ipsec anti-replay window width
Command
system-view
ipsec redundancy enable
Enter IPsec policy view:
ipsec { policy | ipv6-policy }
policy-name seq-number
[ isakmp | manual ]
Enter IPsec policy template
view:
ipsec { policy-template |
ipv6-policy-template }
template-name seq-number
redundancy replay-interval
inbound inbound-interval
outbound outbound-interval
294
Remarks
N/A
By default, IPsec anti-replay is
enabled.
The default size is 64.
Remarks
N/A
By default, IPsec redundancy is
disabled.
N/A
By default, the active device
synchronizes the anti-replay
window every time it receives
1000 packets and the sequence
number every time it sends
100000 packets.

Advertisement

Table of Contents
loading

Table of Contents