488
Usage guidelines
After logging for IPsec packets is enabled, the device outputs a log when an IPsec packet is
discarded. IPsec packets might be discarded due to lack of inbound SA, AH/ESP authentication
failure, or ESP encryption failure. A log contains the source and destination IP addresses, SPI, and
sequence number of the packet, and the reason it was discarded.
Examples
# Enable logging for IPsec packets.
<Sysname> system-view
[Sysname] ipsec logging packet enable
ipsec { ipv6-policy | policy }
Use
ipsec
{
ipv6-policy
|
policy
} to create an IPsec policy entry and enter its view, or enter the view
of an existing IPsec policy entry.
Use
undo
ipsec
{
ipv6-policy
|
policy
} to delete the specified IPsec policy.
Syntax
ipsec
{
ipv6-policy
|
policy
}
policy-name
seq-number
[
gdoi
|
isakmp
|
manual
]
undo
ipsec
{
ipv6-policy
|
policy
}
policy-name
[
seq-number
]
Default
No IPsec policies exist.
Views
System view
Predefined user roles
network-admin
Parameters
ipv6-policy
: Specifies an IPv6 IPsec policy.
policy
: Specifies an IPv4 IPsec policy.
policy-name
: Specifies a name for the IPsec policy, a case-insensitive string of 1 to 63 characters.
seq-number
: Specifies a sequence number for the IPsec policy entry, in the range of 1 to 65535.
gdoi
: Establishes IPsec SAs through GDOI.
isakmp
: Establishes IPsec SAs through IKE negotiation.
manual
: Establishes IPsec SAs manually.
Usage guidelines
When you create an IPsec policy, you must specify the SA setup mode (
gdoi
,
isakmp
, or
manual
).
When you enter the view of an existing IPsec policy, you do not need to specify the SA setup mode.
You cannot change the SA setup mode of an existing IPsec policy.
An IPsec policy is a set of IPsec policy entries that have the same name but different sequence
numbers. In the same IPsec policy, an IPsec policy entry with a smaller sequence number has a
higher priority.
If you specify the
seq-number
argument, the
undo
command deletes the specified IPsec policy
entry. If you do not specify this argument, the
undo
command deletes all entries of the specified
IPsec policy.
An IPv4 IPsec policy and IPv6 IPsec policy can have the same name.