OmniSwitch CLI Reference Guide
March 2011
page 12-1
12 IPsec commands
IPsec is a suite of protocols for securing IPv6 communications by authenticating and/or encrypting each
IPv6 packet in a data stream. IPsec provides security services such as Encrypting traffic, Integrity
validation, Authenticating the peers, and Anti-replay.
IPsec protocols operate at network layer using appropriate security protocols, cryptographic algorithms,
and cryptographic keys. The security services are provided through use of two security protocols, the
Authentication Header (AH) and the Encapsulating Security Payload (ESP), and through the use of
cryptographic key management procedures and protocols.
There are two modes of IPsec operation: transport mode and tunnel mode. In transport mode, only the data
you transfer (payload) in the IPv6 packet is encrypted and/or authenticated and only the payloads that are
originated and destined between two intermediate systems are processed with IPsec. In tunnel mode, the
entire IPv6 packet with both the data and the message headers is encrypted and/or authenticated. In tunnel
mode, all the IPv6 packets that passess through the endpoints are processed by IPsec.
The current imple-
mentation of IPsec supports only the transport mode.
Note.
The current implementation of IPsec supports only IPv6.
The pre-configured Security Policy determines the traffic that is to be rendered with IPsec protection. A
Security Association (SA) specifies the actual IPsec actions to be performed (e.g encryption using 3DES,
authentication with HMAC-SHA1). A security association is bundle of algorithms and parameters (such as
keys) that is being used to encrypt and authenticate a particular flow in one direction. Security
Associations can be manually configured or negotiated through IKE. The current implementation of IPsec
does not support the negotiation of SA through IKE and SAs need to be configured manually.
A summary of the available commands is listed here:
ipsec key
ipsec security-key
ipsec policy
ipsec policy rule
ipsec sa
show ipsec policy
show ipsec sa
show ipsec key
show ipsec ipv6 statistics
Содержание 060321-10, Rev. B
Страница 1: ...Part No 060321 10 Rev B March 2011 OmniSwitch CLI Reference Guide www alcatel lucent com...
Страница 36: ...Technical Support About This Guide page xxxvi OmniSwitch CLI Reference Guide March 2011...
Страница 108: ...show udld status port UDLD Commands page 2 22 OmniSwitch CLI Reference Guide March 2011...
Страница 142: ...show vlan members VLAN Management Commands page 4 16 OmniSwitch CLI Reference Guide March 2011...
Страница 324: ...show linkagg range Link Aggregation Commands page 6 66 OmniSwitch CLI Reference Guide March 2011...
Страница 418: ...show lldp remote system med 802 1AB Commands page 9 40 OmniSwitch CLI Reference Guide March 2011...
Страница 922: ...show ip ospf restart OSPF Commands page 17 88 OmniSwitch CLI Reference Guide March 2011...
Страница 968: ...show ipv6 ospf interface OSPFv3 Commands page 18 46 OmniSwitch CLI Reference Guide March 2011...
Страница 1258: ...show ip slb probes Server Load Balancing Commands page 20 50 OmniSwitch CLI Reference Guide March 2011...
Страница 1414: ...show ip dvmrp tunnel DVMRP Commands page 22 34 OmniSwitch CLI Reference Guide March 2011...
Страница 1535: ...PIM Commands show ipv6 pim groute OmniSwitch CLI Reference Guide March 2011 page 23 121 alaPimStarGIAssertWinnerMetric...
Страница 1540: ...show ipv6 pim sgroute PIM Commands page 23 126 OmniSwitch CLI Reference Guide March 2011...
Страница 1814: ...show policy validity period QoS Policy Commands page 26 174 OmniSwitch CLI Reference Guide March 2011...
Страница 1830: ...show policy server events Policy Server Commands page 27 16 OmniSwitch CLI Reference Guide March 2011...
Страница 1853: ...AAA Commands password OmniSwitch CLI Reference Guide March 2011 page 28 23 aaauPassword aaauOldPassword...
Страница 1877: ...AAA Commands show aaa accounting OmniSwitch CLI Reference Guide March 2011 page 28 47 aaacsName4...
Страница 1888: ...show aaa priv hexa AAA Commands page 28 58 OmniSwitch CLI Reference Guide March 2011...
Страница 1902: ...show port mapping Port Mapping Commands page 29 14 OmniSwitch CLI Reference Guide March 2011...
Страница 1942: ...show port monitoring file Port Mirroring and Monitoring Commands page 31 18 OmniSwitch CLI Reference Guide March 2011...
Страница 1960: ...show sflow poller sFlow Commands page 32 18 OmniSwitch CLI Reference Guide March 2011...
Страница 2014: ...show ethernet service sap profile VLAN Stacking Commands page 34 46 OmniSwitch CLI Reference Guide March 2011...
Страница 2114: ...show mac range alloc Chassis MAC Server CMS Commands page 39 8 OmniSwitch CLI Reference Guide March 2011...
Страница 2188: ...show command log status Session Management Commands page 41 36 OmniSwitch CLI Reference Guide March 2011...
Страница 2226: ...ftp File Management Commands page 42 38 OmniSwitch CLI Reference Guide March 2011...
Страница 2252: ...write terminal Configuration File Manager Commands page 44 18 OmniSwitch CLI Reference Guide March 2011...
Страница 2284: ...show snmp trap config SNMP Commands page 45 32 OmniSwitch CLI Reference Guide March 2011...
Страница 2294: ...show dns DNS Commands page 46 10 OmniSwitch CLI Reference Guide March 2011...
Страница 2350: ...OmniSwitch CLI Reference Guide March 2011 page 22 DNS Commands...