576 CHAPTER 40: CONFIGURING IPSEC

Table 653 Display and Debug IPSec

Operation

Command

 

 

Display all created SA (applicable to IPSec

display ipsec sa all

software)

 

 

 

Display all SA information briefly

display ipsec sa brief

(applicable to IPSec software)

 

 

 

Display the specific SA information

display ipsec sa parameters

(applicable to IPSec software)

dest-address protocol spi

 

 

Display global SA lifetime (applicable to

display ipsec sa duration

IPSec software)

 

 

 

Display SA established with specific peer

display ipsec sa remote ip-address

ends (applicable to IPSec software)

 

 

 

Display all security policy base information

display ipsec sa policy policy-name[

(applicable to IPSec software)

sequence-number ]

 

 

Display statistic information related to

display ipsec statistics

security message (applicable to IPSec

 

software)

 

 

 

Display configured IPSec proposal

display ipsec proposal [

(applicable to IPSec software)

proposal-name ]

 

 

Display all security policy base information

display ipsec policy all

(applicable to IPSec software)

 

 

 

Display brief security policy base

display ipsec policy brief

information (applicable to IPSec software)

 

 

 

Display all security policy base information

display ipsec policy name policy-name

by name (applicable to IPSec software)

[ sequence-number ]

 

 

Clear all SA (applicable to IPSec software)

reset ipsec sa all

 

 

Clear specific SA information (applicable

reset ipsec sa parameters

to IPSec software)

dest-address protocol spi

 

 

Clear SA of the specified security policy

reset ipsec sa policy policy-name[

base (applicable to IPSec software)

sequence-number ]

 

 

Clear SA established with specified peer

reset ipsec sa remote ip-address

ends (applicable to IPSec software)

 

 

 

Clear statistic information related to

reset ipsec statistics

security messages (applicable to IPSec

 

software)

 

 

 

information debugging related to IPSec

debugging ipsec { sa packet misc }

(applicable to IPSec software)

 

 

 

Displaying and

Debugging the NDEC

Card

Resetting the crypto card

When the crypto card operates abnormally, resetting the crypto card can be used to restore the crypto card to normality. When resetting the crypto card, the crypto card restores its initialization. At the same time, the host retransmits the card's configured information and SA information being used to the crypto card. In addition, the host automatically resets the crypto card when it finds that the crypto card operates abnormally.

Configure the following in the system view:

Table 654 Reset crypto card

Operation

Command

 

 

Reset crypto card (applicable to crypto

encrypt-card reset [ slot-id]

card)

 

 

 

Page 580
Image 580
3Com 10014299 manual Display and Debug IPSec, Reset crypto card, Dest-address protocol spi