H3C S6550X-HI Series Command Reference Manual page 2263

Table of Contents

Advertisement

Syntax
ipsec logging negotiation enable
undo ipsec logging negotiation enable
Default
Logging for IPsec negotiation is disabled.
Views
System view
Predefined user roles
network-admin
Usage guidelines
This command enables the device to output logs for the IPsec negotiation process.
Examples
# Enable logging for IPsec negotiation.
<Sysname> system-view
[Sysname] ipsec logging negotiation enable
ipsec logging packet enable
Use
ipsec logging packet enable
Use
undo ipsec logging packet enable
Syntax
ipsec logging packet enable
undo ipsec logging packet enable
Default
Logging for IPsec packets is disabled.
Views
System view
Predefined user roles
network-admin
Usage guidelines
After logging for IPsec packets is enabled, the device outputs a log when an IPsec packet is
discarded. IPsec packets might be discarded due to lack of inbound SA, AH/ESP authentication
failure, or ESP encryption failure. A log contains the source and destination IP addresses, SPI, and
sequence number of the packet, and the reason it was discarded.
Examples
# Enable logging for IPsec packets.
<Sysname> system-view
[
]
Sysname
ipsec logging packet enable
to enable logging for IPsec packets.
to disable logging for IPsec packets.
38

Advertisement

Table of Contents
loading

Table of Contents