Ipsec Apply - H3C MSR Series Command Reference Manual

Comware 7 security
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

Default
The anti-replay window size is 64.
Views
System view
Predefined user roles
network-admin
Parameters
width: Specifies the size for the anti-replay window. It can be 64, 128, 256, 512, or 1024 packets.
Usage guidelines
Changing the anti-replay window size affects only the IPsec SAs negotiated later.
Service data packets might be received in a very different order than their original order, and the
IPsec anti-replay feature might drop them as replayed packets, affecting normal communications. If
this happens, disable IPsec anti-replay checking or adjust the size of the anti-replay window as
required.
Examples
# Set the size of the anti-replay window to 128.
<Sysname> system-view
[Sysname] ipsec anti-replay window 128
Related commands
ipsec anti-replay check

ipsec apply

Use ipsec apply to apply an IPsec policy to an interface.
Use undo ipsec apply to remove an IPsec policy application from an interface.
Syntax
ipsec apply { ipv6-policy | policy } policy-name
undo ipsec apply { ipv6-policy | policy }
Default
No IPsec policy is applied to an interface.
Views
Interface view
Predefined user roles
network-admin
Parameters
ipv6-policy: Specifies an IPv6 IPsec policy.
policy: Specifies an IPv4 IPsec policy.
policy-name: Specifies an IPsec policy name, a case-insensitive string of 1 to 63 characters.
Usage guidelines
On an interface, you can apply a maximum of two IPsec policies: one IPv4 IPsec policy and one IPv6
IPsec policy.
537

Advertisement

Table of Contents
loading

Table of Contents