Step 24 (Optional) Run:
quit
Return to the system view.
Step 25 Run:
interface interface-type interface-number
The interface view is displayed.
Step 26 Run:
ipsec efficient-vpn efficient-vpn-name
The Efficient VPN policy is applied to the interface.
----End
5.6.4 Verifying the Configuration
After completing Efficient VPN configuration, you can view information about the IPSec
proposal, SA, IPSec Efficient VPN policy, and IPSec tunnel established using the Efficient VPN
policy.
Prerequisites
All Efficient VPN configurations are complete.
Procedure
l Run the display ike sa [ v2 ] [ conn-id connid | peer-name peername | phase phase-
number | verbose ] command to check information about the IPSec tunnel established
through IKE negotiation.
l Run the display ipsec sa [ brief | duration | policy policy-name [ seq-number ] | profile
profile-name | efficient-vpn efficient-vpn-name | peerip peer-ip-address ] command to
check information about SAs.
l Run the display ipsec proposal [ name proposal-name ] command to check information
about IPSec proposals.
l Run the display ipsec efficient-vpn [ brief | capality | name efficient-vpn-name ] command
to check information about the Efficient VPN policy.
----End
5.7 Maintaining IPSec
This section describes how to display the IPSec configuration and clear the IPSec statistics.
5.7.1 Displaying the IPSec Configuration
You can run the following display commands to view information about the SA, established
IPSec tunnel, and statistics about IPSec packets.
Prerequisites
The configurations of IPSec are complete.
Huawei AR1200 Series Enterprise Routers
Configuration Guide - VPN 5 IPSec Configuration
Issue 01 (2012-04-20) Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
313