Examples
# Set the DF bit in the outer IP header of IPsec packets on all interfaces.
<Sysname> system-view
[Sysname] ipsec global-df-bit set
Related commands
ipsec df-bit
ipsec limit max-tunnel
Use ipsec limit max-tunnel to set the maximum number of IPsec tunnels.
Use undo ipsec limit max-tunnel to restore the default.
Syntax
ipsec limit max-tunnel tunnel-limit
undo ipsec limit max-tunnel
Views
System view
Predefined user roles
network-admin
Parameters
tunnel-limit: Specifies the maximum number of IPsec tunnels, in the range of 1 to 4294967295.
Usage guidelines
A greater number of IPsec tunnels bring higher concurrent performance of IPsec but use more
memory space. Adjust the maximum number of IPsec tunnels according to the size of free memory
space.
Examples
# Set the maximum number of IPsec tunnels to 5000.
<Sysname> system-view
[Sysname] ipsec limit max-tunnel 5000
Related commands
ike limit
ipsec logging negotiation enable
Use ipsec logging negotiation enable to enable logging for IPsec negotiation.
Use undo ipsec logging negotiation packet enable to disable logging for IPsec negotiation.
Syntax
ipsec logging negotiation enable
undo ipsec logging negotiation enable
Default
Logging for IPsec negotiation is disabled.
Views
System view
541