2130
C
140: IPS
HAPTER
EC
encapsulation-mode
Syntax
View
Parameter
Description
Related command:
Example
encrypt-card fast-switch
Syntax
View
C
C
ONFIGURATION
OMMANDS
Dest Addr : 44.44.44.0/255.255.255.0
Current Encrypt-card: None
Table 568 Description on the fields of the display ipsec tunnel command
Field
Connection ID
Perfect forward secrecy
SA's SPI
Tunnel
Flow
Current Encrypt-card
encapsulation-mode { transport | tunnel }
undo encapsulation-mode
IPSec proposal view
transport: Uses transport mode.
tunnel: Uses tunnel mode.
Use the
encapsulation-mode
transport or tunnel) that the security protocol uses to encapsulate IP packets.
Use the
undo encapsulation-mode
By default, a security protocol encapsulates IP packets in tunnel mode.
ipsec proposal.
# Configure IPSec proposal prop2 to encapsulate IP packets in transport mode.
<Sysname> system-view
[Sysname] ipsec proposal prop2
[Sysname-ipsec-proposal-prop2] encapsulation-mode transport
encrypt-card fast-swtich
undo encrypt-card fast-switch
System view
Description
Connection ID, used to uniquely identify an IPSec Tunnel
Perfect forward secrecy, indicating which DH group is to be
used for fast negotiation mode in IKE phase 2
SPIs of the inbound and outbound SAs
Local and remote addresses of the tunnel
Data flow protected by the IPSec tunnel, including source IP
address, destination IP address, source port, destination port
and protocol
Encryption card interface used by the current tunnel
command to set the encapsulation mode (either
command to restore the default.
Port: 0
Protocol : IP