Ipsec Limit Max-Tunnel; Ipsec Logging Negotiation Enable - H3C MSR Series Command Reference Manual

Comware 7 security
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

Examples
# Set the DF bit in the outer IP header of IPsec packets on all interfaces.
<Sysname> system-view
[Sysname] ipsec global-df-bit set
Related commands
ipsec df-bit

ipsec limit max-tunnel

Use ipsec limit max-tunnel to set the maximum number of IPsec tunnels.
Use undo ipsec limit max-tunnel to restore the default.
Syntax
ipsec limit max-tunnel tunnel-limit
undo ipsec limit max-tunnel
Views
System view
Predefined user roles
network-admin
Parameters
tunnel-limit: Specifies the maximum number of IPsec tunnels, in the range of 1 to 4294967295.
Usage guidelines
A greater number of IPsec tunnels bring higher concurrent performance of IPsec but use more
memory space. Adjust the maximum number of IPsec tunnels according to the size of free memory
space.
Examples
# Set the maximum number of IPsec tunnels to 5000.
<Sysname> system-view
[Sysname] ipsec limit max-tunnel 5000
Related commands
ike limit

ipsec logging negotiation enable

Use ipsec logging negotiation enable to enable logging for IPsec negotiation.
Use undo ipsec logging negotiation packet enable to disable logging for IPsec negotiation.
Syntax
ipsec logging negotiation enable
undo ipsec logging negotiation enable
Default
Logging for IPsec negotiation is disabled.
Views
System view
541

Advertisement

Table of Contents
loading

Table of Contents