3Com 3C13636 Configuration Manual page 1148

Router 3000 ethernet family
Hide thumbs Also See for 3C13636:
Table of Contents

Advertisement

3Com Router 3000 Ethernet Family
Configuration Guide
[3Com] ipsec policy map1 10 isakmp
[3Com-ipsec-policy-isakmp-map1-10] proposal tran1
[3Com-ipsec-policy-isakmp-map1-10] security acl 3101
[3Com-ipsec-policy-isakmp-map1-10] ike-peer peer
[3Com-ipsec-policy-isakmp-map1-10] quit
# Apply an IPSec policy group to the interface.
[3Com] interface ethernet 0/0/0
[3Com-Ethernet 0/0/0] ip address 13.0.0.1 255.0.0.0
[3Com-Ethernet 0/0/0] ipsec policy map1
[3Com-Ethernet 0/0/0] quit
# Configure an Ethernet interface.
[3Com] interface ethernet 1/0/0
[3Com-Ethernet1/0/0] ip address 12.0.0.2 255.255.255.0
Execute the ping -c 500 11.0.0.7 command on host B to ping PC A, and then execute
the display ike sa and display ipsec sa commands on Router A and Router E
respectively to display established SAs.
Execute the shutdown command on interface Ethernet 0/0/0 on Router A. Then
execute the debugging ike dpd command on Router E. You may find out that a DPD
query is sent three times, but no acknowledgement is received. Then, all SAs on the
involved peer are deleted, while failover is happening in the VRRP standby group.
About 10 seconds later, the security tunnel is recovered. The following debugging
information is displayed:
<3Com> debugging ike dpd
(SAs are deleted after three DPD query attempts are failed.)
RouterE
(seqno:-12903966)
RouterE IKE/8/DEBUG:REQUEST: wait for response timeout
RouterE
(seqno:-1917909230
RouterE IKE/8/DEBUG:REQUEST: wait for response timeout
RouterE
(seqno:-1183268982)
RouterE IKE/8/DEBUG:REQUEST: wait for response timeout
RouterE IKE/8/DEBUG:REQUEST: there are three fail and all SAs associated were
deleted
(A response is received from the peer after the failover completes in its corresponding
VRRP standby group)
RouterE
(seqno:1382148220)
RouterE
IKE/8/DEBUG:REQUEST(send
IKE/8/DEBUG:REQUEST(send
IKE/8/DEBUG:REQUEST(send
IKE/8/DEBUG:REQUEST(send
IKE/8/DEBUG:REQUEST(recv
3Com Corporation
dpd
request):
dpd
request):
dpd
request):
dpd
request):
dpd
response):
7-44
Chapter 7 IPSec Configuration
send
a
message
send
a
message
send
a
message
send
a
message
received
a
message

Advertisement

Table of Contents
loading

This manual is also suitable for:

3c13636-us - router 30363000 series

Table of Contents