Configuring The Df Bit Of Ipsec Packets - HP FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Step
1.
Enter system view.
2.
Enter IPsec policy view or
IPsec policy template view.
3.
Enable IPsec RRI.
4.
(Optional.) Set the
preference value for the
static routes created by
IPsec RRI.
5.
(Optional.) Set the tag value
for the static routes created
by IPsec RRI.

Configuring the DF bit of IPsec packets

Perform this task to configure the Don't Fragment (DF) bit in the new IP header of IPsec packets in
one of the following ways:
clear—Clears the DF bit in the new header.
set—Sets the DF bit in the new header.
copy—Copies the DF bit in the original IP header to the new IP header.
You can configure the DF bit in system view and interface view. The interface-view DF bit setting
takes precedence over the system-view DF bit setting. If the interface-view DF bit setting is not
configured, the interface uses the system-view DF bit setting.
Follow these guidelines when you configure the DF bit:
The DF bit setting takes effect only in tunnel mode, and it changes the DF bit in the new IP
header rather than the original IP header.
Configure the same DF bit setting on the interfaces where the same IPsec policy bound to a
source interface has been applied.
If the DF bit is set, the devices on the path cannot fragment the IPsec packets. Therefore, make
sure the path MTU is larger than the IPsec packets. Otherwise, the IPsec packets will be
discarded. If the path MTU is smaller than the IPsec packets, clear the DF bit.
To configure the DF bit of IPsec packets on an interface:
Step
1.
Enter system view.
Command
system-view
To enter IPsec policy view:
ipsec { policy | ipv6-policy }
policy-name seq-number
isakmp
To enter IPsec policy template
view:
ipsec { policy-template |
ipv6-policy-template }
template-name seq-number
reverse-route dynamic
reverse-route preference number
reverse-route tag tag-value
Command
system-view
297
Remarks
N/A
N/A
By default, IPsec RRI is
disabled.
IPsec RRI is supported in both
tunnel mode and transport
mode.
The default value is 60.
The default value is 0.
Remarks
N/A

Advertisement

Table of Contents
loading

Table of Contents