Configuring the IPSec
Session Idle Timeout
Enabling Encryption
Card Fast Forwarding
an encryption card failure. On contrary, the encryption switch fabric and the IPSec
module can backup each other. The IPSec module can automatically substitute the
encryption switch fabric for IPSec processing when the encryption switch fabric
fails.
Follow these steps to enable the IPSec module backup function:
To do...
Enter system view
Enable the IPSec module
backup function
An IPSec session is created when the first packet matching an IPSec policy arrives.
Also created is an IPSec session entry, which records the quintuplet (source IP
address, destination IP address, protocol number, source port and destination port)
and the matched IPSec tunnel.
An IPSec session is automatically deleted after the idle timeout expires.
Subsequent data flows search the session entries according to the quintuplet to
find a matched item. If found, the data flows are processed according to the
tunnel information; otherwise, they are processed according to the original IPSec
process: search the policy group or policy at the interface, and then the matched
tunnel.
The session processing mechanism of IPSec saves intermediate matching
procedures and there improves IPSec forwarding efficiency.
Follow these steps to set the IPSec session idle timeout:
To do...
Enter system view
Set the IPSec session idle
timeout
The fast forwarding function of encryption card is to create an index entry (called a
fast forwarding entry) when IPSec processes the first packet, including the IP
addresses at the inbound and outbound direction. Then subsequent packets will
try to match this entry first. If matched, IPSec forwards the packets directly to the
encryption card for processing. As a result, this can save the intermediate
matching procedures and system resources, and thus improving IPSec processing
efficiency.
Follow these steps to enable encryption card fast forwarding:
To do...
Enter system view
Configuring the IPSec Session Idle Timeout
Use the command...
system-view
ipsec cpu-backup enable
Use the command...
system-view
ipsec session idle-time
seconds
Use the command...
system-view
1889
Remarks
-
Required
Disabled by default
Remark
-
Optional
300 seconds by default
Remark
-
Need help?
Do you have a question about the MSR 50 Series and is the answer not in the manual?