Command Reference
138
ETEP CLI User Guide
applicable). Use the
show-policy-set
command to view the active and pending policies. The
show-ike-
params
lets you review the global settings used for IKE negotiations in management port policies.
If you find that the deployed policies are not executing as expected, you can restore the backup policies
to revert to the previously executing set of policies.
Related topic:
●
Example
The following example deploys policies to the ETEP management port.
config>
management-interface
man-if>
ipsec-config
ipsec-config>
deploy-policy-set
dfbit-ignore
Description
The
dfbit-ignore
command determines whether the ETEP ignores the DF bit in the IP header or acts in
accordance the DF bit setting.
User Type
Administrator
Hierarchy Level
Local interface configuration mode (config > local-interface)
Syntax
dfbit-ignore {on | off}
Attributes
on –
The ETEP ignores the DF bit in the IP header and fragments outbound packets greater than the
MTU of the system. When the reassembly command is set to
gateway
, the ETEP sets the dfbit-ignore
command to
on
. This is the default setting.
off –
The ETEP acts in accordance with the DF bit setting in the IP header.
Usage Guidelines
When the ETEP is configured for use in Layer 3 IP encryption policies, its default behavior is to ignore
the “do not fragment” (DF) bit in the IP header, and fragment outbound packets that exceed the MTU of
the system. This setting should be used under the following conditions:
●
Reassembly mode is set to
gateway
●
ICMP is blocked at the firewall
●
PMTU path discovery isn’t working
Содержание ET0010A
Страница 7: ...8 ETEP CLI User Guide Contents...
Страница 15: ...Getting Started 16 ETEP CLI User Guide...
Страница 33: ...User Administration 34 ETEP CLI User Guide...
Страница 55: ...Configuring the ETEP 56 ETEP CLI User Guide...
Страница 97: ...Creating Policies 98 ETEP CLI User Guide...
Страница 101: ...Maintenance 102 ETEP CLI User Guide...
Страница 119: ...Troubleshooting 120 ETEP CLI User Guide...
Страница 123: ...FIPS 140 2 Level 2 Operation 124 ETEP CLI User Guide...
Страница 205: ...Command Reference 206 ETEP CLI User Guide...
Страница 211: ...Index 212 ETEP CLI User Guide...