EasyManuals Logo
Home>HP>Switch>FlexFabric 5700 series

HP FlexFabric 5700 series User Manual

HP FlexFabric 5700 series
460 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #277 background imageLoading...
Page #277 background image
265
Ste
Command
Remarks
1. Enter system view.
system-view N/A
2. Enable ACL checking for
de-encapsulated packets.
ipsec decrypt-check enable By default, this feature is enabled.
Configuring the IPsec anti-replay function
The IPsec anti-replay function protects networks against anti-replay attacks by using a sliding window
mechanism called anti-replay window. This function checks the sequence number of each received IPsec
packet against the current IPsec packet sequence number range of the sliding window. If the sequence
number is not in the current sequence number range, the packet is considered a replayed packet and is
discarded.
IPsec packet de-encapsulation involves complicated calculation. De-encapsulation of replayed packets is
not required, and the de-encapsulation process consumes large amounts of resources and degrades
performance, resulting in DoS. IPsec anti-replay can check and discard replayed packets before
de-encapsulation.
In some situations, service data packets are received in a different order than their original order. The
IPsec anti-replay function drops them as replayed packets, which impacts communications. If this
happens, disable IPsec anti-replay checking or adjust the size of the anti-replay window as required.
IPsec anti-replay does not affect manually created IPsec SAs. According to the IPsec protocol, only
IKE-based IPsec SAs support anti-replay checking.
IMPORTANT:
• IPsec anti-replay is enabled by default. Failure to detect anti-replay attacks might result in denial of
services. Use caution when you disable IPsec anti-replay.
• Specify an anti-replay window size that is as small as possible to reduce the impact on system
performance.
• Typically, an IRF fabric processes packets for a VLAN interface or tunnel interface directly on the
member devices that received the packets. However, IPsec anti-replay requires packets sent and received
on the same VLAN interface or tunnel interface be processed by the same member device. To implemen
t
IPsec anti-replay in an IRF fabric, use the service slot
slot-number
command in VLAN interface view to
specify a member device for forwarding the traffic on the interface. For more information about the
service command, see
Layer 2—LAN Switching Command Reference
.
To configure IPsec anti-replay:
Ste
Command
Remarks
1. Enter system view.
system-view N/A
2. Enable IPsec anti-replay.
ipsec anti-replay check
By default, IPsec anti-replay is
enabled.
3. Set the size of the IPsec
anti-replay window.
ipsec anti-replay window width The default size is 64.

Table of Contents

Other manuals for HP FlexFabric 5700 series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HP FlexFabric 5700 series and is the answer not in the manual?

HP FlexFabric 5700 series Specifications

General IconGeneral
BrandHP
ModelFlexFabric 5700 series
CategorySwitch
LanguageEnglish

Related product manuals