296
Step Command
Remarks
2.
Enter IPsec policy view or
IPsec policy template view.
•
To enter IPsec policy view:
ipsec
{
policy
|
ipv6-policy
}
policy-name
seq-number
[
isakmp
|
manual
]
•
To enter IPsec policy
template view:
ipsec
{
policy-template
|
ipv6-policy-template
}
template-name
seq-number
N/A
3.
Enable QoS pre-classify.
qos pre-classify
By default, QoS pre-classify is
disabled.
Enabling logging of IPsec packets
Perform this task to enable the logging of IPsec packets that are discarded because of reasons such
as IPsec SA lookup failure, AH-ESP authentication failure, and ESP encryption failure. The log
information includes the source and destination IP addresses, the SPI value, and the sequence
number of a discarded IPsec packet, and the reason for the failure.
To enable the logging of IPsec packets:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable the logging of IPsec
packets.
ipsec logging packet enable
By default, the logging of IPsec
packets is disabled.
Configuring IPsec RRI
Configuration guidelines
When you enable or disable IPsec RRI for an IPsec policy, the device deletes all IPsec SAs created
by this IPsec policy, and the associated static routes.
If you change the preference value or tag value for an IPsec policy, the device deletes all IPsec SAs
created by this IPsec policy, and the associated static routes. Your change takes effect for future
IPsec RRI-created static routes.
You can set preferences for the static routes created by IPsec RRI to flexibly apply route
management policies. For example, you can set the same preference for multiple routes to the same
destination to implement load sharing, or you can set different preferences to implement route
backup.
You can also set tags for the static routes created by IPsec RRI to implement flexible route control
through routing policies.
IPsec RRI does not generate a static route to a destination address to be protected if the destination
address is not defined in the ACL used by an IPsec policy or an IPsec policy template. You must
manually configure a static route to the destination address.
Configuration procedure
To configure IPsec RRI:
Summary of Contents for 10500 series
Page 326: ...312 No duration limit for this SA ...