300
displays notifications. For more information about SNMP notifications, see
Network Management
and Monitoring Configuration Guide
.
To generate and output SNMP notifications for a specific IPsec failure or event type, perform the
following tasks:
1.
Enable SNMP notifications for IPsec globally.
2.
Enable SNMP notifications for the failure or event type.
To configure SNMP notifications for IPsec:
Step Command Remarks
1.
Enter system view
system-view
N/A
2.
Enable SNMP
notifications for IPsec
globally.
snmp-agent
trap
enable
ipsec
global
By default, SNMP notifications for
IPsec are disabled.
3.
Enable SNMP
notifications for the
specified failure or event
types.
snmp-agent
trap
enable
ipsec
[
auth-failure
|
decrypt-failure
|
encrypt-failure
|
invalid-sa-failure
|
no-sa-failure
|
policy-add
|
policy-attach
|
policy-delete
|
policy-detach
|
tunnel-start
|
tunnel-stop
] *
By default, SNMP notifications for
all failure and event types are
disabled.
Displaying and maintaining IPsec
Execute
display
commands in any view and
reset
commands in user view.
Task Command
Display IPsec policy information.
display
ipsec
{
ipv6-policy
|
policy
} [
policy-name
[
seq-number
] ]
Display IPsec policy template information.
display
ipsec
{
ipv6-policy-template
|
policy-template
} [
template-name
[
seq-number
] ]
Display IPsec profile information.
display ipsec profile
[
profile-name
]
Display IPsec transform set information.
display ipsec transform-set
[
transform-set-name
]
Display IPsec SA information.
display
ipsec
sa
[
brief
|
count
|
interface
interface-type
interface-number
| {
ipv6-policy
|
policy
}
policy-name
[
seq-number
] |
profile
policy-name
|
remote
[
ipv6
]
ip-address
]
Display IPsec statistics.
display ipsec statistics
[
tunnel-id
tunnel-id
]
Display IPsec tunnel information.
display ipsec tunnel
{
brief
|
count
|
tunnel-id
tunnel-id
}
Clear IPsec SAs.
reset
ipsec
sa
[ {
ipv6-policy
|
policy
}
policy-name
[
seq-number
] |
profile
policy-name
|
remote
{
ipv4-address
|
ipv6
ipv6-address
}
|
spi
{
ipv4-address
|
ipv6
ipv6-address
} {
ah
|
esp
}
spi-num
]
Clear IPsec statistics.
reset ipsec statistics
[
tunnel-id
tunnel-id
]
Summary of Contents for 10500 series
Page 326: ...312 No duration limit for this SA ...