318
Step Command Remarks
sa hex-key authentication
{
inbound
|
outbound
}
esp
{
cipher
|
simple
}
string
•
Configure an encryption key in
hexadecimal format for ESP:
sa hex-key encryption
{
inbound
|
outbound
}
esp
{
cipher
|
simple
}
string
Configuring SNMP notifications for IPsec
After you enable SNMP notifications for IPsec, the IPsec module notifies the NMS of important
module events. The notifications are sent to the device's SNMP module. You can configure the
notification transmission parameters for the SNMP module to specify how the SNMP module
displays notifications. For more information about SNMP notifications, see
Network Management
and Monitoring Configuration Guide
.
To generate and output SNMP notifications for a specific IPsec failure or event type, perform the
following tasks:
1.
Enable SNMP notifications for IPsec globally.
2.
Enable SNMP notifications for the failure or event type.
To configure SNMP notifications for IPsec:
Step Command Remarks
1.
Enter system view
system-view
N/A
2.
Enable SNMP
notifications for IPsec
globally.
snmp-agent
trap
enable
ipsec
global
By default, SNMP notifications for
IPsec are disabled.
3.
Enable SNMP
notifications for the
specified failure or event
types.
snmp-agent
trap
enable
ipsec
[
auth-failure
|
decrypt-failure
|
encrypt-failure
|
invalid-sa-failure
|
no-sa-failure
|
policy-add
|
policy-attach
|
policy-delete
|
policy-detach
|
tunnel-start
|
tunnel-stop
] *
By default, SNMP notifications for
all failure and event types are
disabled.
Configuring IPsec fragmentation
Perform this task to configure the device to fragment packets before or after IPsec encapsulation.
If you configure the device to fragment packets before IPsec encapsulation, the device
predetermines the encapsulated packet size before the actual encapsulation. If the encapsulated
packet size exceeds the MTU of the output interface, the device fragments the packets before
encapsulation. If a packet's DF bit is set, the device drops the packet and sends an ICMP error
message.
If you configure the device to fragment packets after IPsec encapsulation, the device directly
encapsulates the packets and fragments the encapsulated packets in subsequent service modules.
This feature takes effect on IPsec protected IPv4 packets.
To configure IPsec fragmentation:
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...