Configuring Ipsec Anti-Replay Redundancy - HPE Moonshot 45Gc Security Configuration Manual

Switch module
Table of Contents

Advertisement

IMPORTANT:
• IPsec anti-replay is enabled by default. Failure to detect anti-replay attacks might result in denial
of services. Use caution when you disable IPsec anti-replay.
• Specify an anti-replay window size that is as small as possible to reduce the impact on system
performance.
• Typically, an IRF fabric processes packets for a VLAN interface or tunnel interface directly on the
member devices that received the packets. However, IPsec anti-replay requires packets sent
and received on the same VLAN interface or tunnel interface be processed by the same member
device. To implement IPsec anti-replay in an IRF fabric, use the service slot slot-number
command in VLAN or tunnel interface view to specify a member device for forwarding the traffic
on the interface. For more information about the service command, see Layer 2—LAN Switching
Command Reference or Layer 3—IP Services Command Reference.
To configure IPsec anti-replay:
Step
1.
Enter system view.
2.
Enable IPsec anti-replay.
3.
Set the size of the IPsec
anti-replay window.

Configuring IPsec anti-replay redundancy

This feature synchronizes the following information from the master device to all subordinate devices
in an IRF fabric at configurable packet-based intervals:
Lower bound values of the IPsec anti-replay window for inbound packets.
IPsec anti-replay sequence numbers for outbound packets.
This feature, used together with IPsec redundancy, ensures uninterrupted IPsec traffic forwarding
and anti-replay protection when the master device in an IRF fabric fails.
To configure IPsec anti-replay redundancy:
Step
1.
Enter system view.
2.
Enable IPsec redundancy.
3.
Enter IPsec policy view or
IPsec policy template view.
4.
Set the anti-replay window
synchronization interval for
inbound packets and the
sequence number
synchronization interval for
Command
system-view
ipsec anti-replay check
ipsec anti-replay window width
Command
system-view
ipsec redundancy enable
Enter IPsec policy view:
ipsec { policy | ipv6-policy }
policy-name seq-number
[ isakmp | manual ]
Enter IPsec policy template
view:
ipsec { policy-template |
ipv6-policy-template }
template-name seq-number
redundancy replay-interval
inbound inbound-interval
outbound outbound-interval
273
Remarks
N/A
By default, IPsec anti-replay is
enabled.
The default size is 64.
Remarks
N/A
By default, IPsec redundancy is
disabled.
N/A
By default, the master device
synchronizes the anti-replay
window every time it receives
1000 packets and the sequence
number every time it sends

Advertisement

Table of Contents
loading

Table of Contents