Diagnostic Commands
Chapter 5. Troubleshooting
59
Response
The command response displays precisely what the HA4000 is enforcing and in
what order (see Table 5-5). Given a packet with specific selectors, you can
determine how the packet will be handled by checking it against the SPD in
descending order.
The
all
attribute provides a detailed view of the SPD for technical support use.
Table 5-5 SPD Selectors
SPD Selector
Description
Direction
Inbound packets enter the remote port from the
untrusted network. Outbound packets enter the local
port from the trusted network.
Policy
The policy type is displayed as Clear, Drop (discard), or
IPSec (either manual key or negotiated IPSec).
Encap?
•
No
selects packets that do not have ESP or AH
encapsulation.
•
Yes
selects ESP or AH encapsulated packets. An
outbound packet will never have a Yes selector for
encapsulation
•
*
(asterisk) indicates “don’t care.”
Source Address –
Protocol Port
Displays the source and destination IP addresses,
subnet masks, ports, and protocol selectors.