H3C MSR Series Command Reference Manual page 606

Comware 7 security
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

Table 87 Command output
Field
Connection ID
Outside VPN
Inside VPN
Profile
Transmitting entity
Local IP
Local ID type
Local ID
Remote IP
Remote ID type
Remote ID
Authentication-method
Authentication-algorithm
Encryption-algorithm
Life duration(sec)
Remaining key duration(sec)
Exchange-mode
Diffie-Hellman group
NAT traversal
Extend authentication
Assigned IP address
Description
Identifier of the IKE SA.
VPN instance name of the MPLS L3VPN to which the receiving
interface belongs.
VPN instance name of the MPLS L3VPN to which the protected data
belongs.
Name of the matching IKE profile found in the IKE SA negotiation.
If no matching profile is found, this field displays nothing.
Role of the IKE negotiation entity: Initiator or Responder.
IP address of the local gateway.
Identifier type of the local gateway.
Identifier of the local gateway.
IP address of the remote gateway.
Identifier type of the remote gateway.
Identifier of the remote security gateway.
Authentication method used by the IKE proposal.
Authentication algorithm used by the IKE proposal:
MD5—HMAC-MD5 algorithm.
SHA1—HMAC-SHA1 algorithm.
SHA256—HMAC-SHA256 algorithm.
SHA384—HMAC-SHA384 algorithm.
SHA512—HMAC-SHA512 algorithm.
SM3—HMAC-SM3 algorithm.
Encryption algorithm used by the IKE proposal:
3DES-CBC—168-bit 3DES algorithm in CBC mode.
AES-CBC-128—128-bit AES algorithm in CBC mode.
AES-CBC-192—192-bit AES algorithm in CBC mode.
AES-CBC-256—256-bit AES algorithm in CBC mode.
DES-CBC—56-bit DES algorithm in CBC mode.
SM1-CBC-128—128-bit SM1 algorithm in CBC mode.
SM1-CBC-192—192-bit SM1 algorithm in CBC mode.
SM1-CBC-256—256-bit SM1 algorithm in CBC mode.
SM4-CBC-128—128-bit SM4 algorithm in CBC mode.
Lifetime of the IKE SA in seconds.
Remaining lifetime of the IKE SA in seconds.
IKE negotiation mode in phase 1: main mode or aggressive mode.
DH group used for key negotiation in IKE phase 1.
Whether a NAT gateway is detected.
Whether extended authentication for clients is enabled.
IP address assigned to the remote peer.
This field is not displayed if no IP address is assigned.
583

Advertisement

Table of Contents
loading

Table of Contents