58
# Specify IPv4 advanced ACL 3002 for IPsec policy
policy2
and specify the data protection mode as
aggregation.
<Sysname> system-view
[Sysname] acl advanced 3002
[Sysname-acl-ipv4-adv-3002] rule 0 permit ip source 10.1.2.1 0.0.0.255 destination
10.1.2.2 0.0.0.255
[Sysname-acl-ipv4-adv-3002] rule 1 permit ip source 10.1.3.1 0.0.0.255 destination
10.1.3.2 0.0.0.255
[Sysname-acl-ipv4-adv-3002] quit
[Sysname] ipsec policy policy2 1 isakmp
[Sysname-ipsec-policy-isakmp-policy2-1] security acl 3002 aggregation
Related commands
display ipsec sa
display ipsec tunnel
snmp-agent trap enable ipsec
Use
snmp-agent trap enable ipsec
command to enable SNMP notifications for IPsec.
Use
undo snmp-agent
trap
enable
ipsec
command to disable SNMP notifications for IPsec.
Syntax
snmp-agent
trap
enable
ipsec
[
auth-failure
|
decrypt-failure
|
encrypt-failure
|
global
|
invalid-sa-failure
|
no-sa-failure
|
policy-add
|
policy-attach
|
policy-delete
|
policy-detach
|
tunnel-start
|
tunnel-stop
]
*
undo snmp-agent
trap
enable
ipsec
[
auth-failure
|
decrypt-failure
|
encrypt-failure
|
global
|
invalid-sa-failure
|
no-sa-failure
|
policy-add
|
policy-attach
|
policy-delete
|
policy-detach
|
tunnel-start
|
tunnel-stop
]
*
Default
All SNMP notifications for IPsec are disabled.
Views
System view
Predefined user roles
network-admin
Parameters
auth-failure
: Specifies notifications about authentication failures.
decrypt-failure
: Specifies notifications about decryption failures.
encrypt-failure
: Specifies notifications about encryption failures.
global
: Specifies notifications globally.
invalid-sa-failure
: Specifies notifications about invalid-SA failures.
no-sa-failure
: Specifies notifications about SA-not-found failures.
policy-add
: Specifies notifications about events of adding IPsec policies.
policy-attach
: Specifies notifications about events of applying IPsec policies to interfaces.
Summary of Contents for SOHO IE4300
Page 285: ...i Contents Tcl commands 1 cli 1 tclquit 1 tclsh 2...
Page 288: ...i Contents Python commands 1 exit 1 python 1 python filename 2...
Page 291: ...i Contents Automatic configuration commands 1 autodeploy udisk enable 1...
Page 323: ...25 Sysname Ten GigabitEthernet1 0 51 undo shutdown Related commands irf port...
Page 465: ...ii stp vlan enable 55 vlan mapping modulo 55...
Page 602: ...12 Related commands display mvrp statistics...
Page 609: ...i Contents VLAN mapping commands 1 display vlan mapping 1 vlan mapping 2...
Page 678: ...9 Related commands reset pppoe relay statistics...
Page 846: ...i Contents Basic IP forwarding commands 1 display fib 1 ip forwarding table save 2...
Page 1770: ...i Contents Time range commands 1 display time range 1 time range 1...
Page 2026: ...34 Related commands display mac authentication...
Page 2028: ...ii...
Page 2143: ...i Contents User profile commands 1 display user profile 1 user profile 2...
Page 2308: ...61 ipsec transform set...
Page 2531: ...i Contents SAVI commands 1 ipv6 savi down delay 1 ipv6 savi log enable 1 ipv6 savi strict 2...
Page 2534: ...3 Sysname ipv6 savi strict Related commands ipv6 verify source...
Page 2791: ...14 Sysname track 1 Related commands delay display track...
Page 2939: ...9 sntp authentication keyid sntp reliable authentication keyid...
Page 2967: ...27 Related commands apply poe profile poe enable poe max power interface view poe priority...