Ipsec Global-Df-Bit - H3C MSR Series Command Reference Manual

Comware 7 security
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

Parameters
after-encryption: Fragments packets after IPsec encapsulation.
before-encryption: Fragments packets before IPsec encapsulation.
Usage guidelines
If you configure the device to fragment packets before IPsec encapsulation, the device
predetermines the encapsulated packet size before the actual encapsulation. If the encapsulated
packet size exceeds the MTU of the output interface, the device fragments the packets before
encapsulation. If a packet's DF bit is set, the device drops the packet and sends an ICMP error
message.
If you configure the device to fragment packets after IPsec encapsulation, the device directly
encapsulates the packets and fragments the encapsulated packets in subsequent service modules.
Examples
# Configure the device to fragment packets after IPsec encapsulation.
<Sysname>system-view
[Sysname] ipsec fragmentation after-encryption

ipsec global-df-bit

Use ipsec global-df-bit to configure the DF bit for the outer IP header of IPsec packets on all
interfaces.
Use undo ipsec global-df-bit to restore the default.
Syntax
ipsec global-df-bit { clear | copy | set }
undo ipsec global-df-bit
Default
The DF bit setting of the original IP header is copied to the outer IP header for IPsec packets.
Views
System view
Predefined user roles
network-admin
Parameters
clear: Clears the DF bit in the outer IP header. IPsec packets can be fragmented.
copy: Copies the DF bit setting of the original IP header to the outer IP header.
set: Sets the DF bit in the outer IP header. IPsec packets cannot be fragmented.
Usage guidelines
This command is effective only when the IPsec encapsulation mode is tunnel mode. It is not effective
in transport mode because the outer IP header is not added in transport mode.
This command does not change the DF bit for the original IP header of IPsec packets.
Packet fragmentation and reassembly might cause packet forwarding to be delayed. You can set the
DF bit to avoid the forwarding delay. However, to prevent IPsec packets from being discarded, you
must make sure the path MTU is larger than the IPsec packet size. As a best practice, clear the DF
bit if you cannot make sure the path MTU is larger than the IPsec packet size.
540

Advertisement

Table of Contents
loading

Table of Contents