F3726, F3211, F3174, R5135, R3816-HP Firewalls and UTM Devices VPN Configuration Guide-6PW100
187
454BConfiguration procedure
To implement IPsec stateful failover on two devices, you must enable IPsec stateful failover on both
devices.
To configure IPsec stateful failover on a device:
Ste
p
Command
Remarks
1. Enter system view.
system-view N/A
2. Enable IPsec stateful
failover.
ipsec synchronization enable
By default, IPsec stateful
failover is enabled.
211BDisplaying and maintaining IPsec
Task Command
Remarks
Display IPsec policy information.
display ipsec policy [ brief | name
policy-name [ seq-number ] ] [ | { begin |
exclude | include } regular-expression ]
Available in any view.
Display IPsec policy template
information.
display ipsec policy-template [ brief |
name template-name [ seq-number ] ] [ |
{ begin | exclude | include }
regular-expression ]
Available in any view.
Display the configuration of IPsec
profiles.
display ipsec profile [ name
profile-name ] [ | { begin | exclude |
include } regular-expression ]
Available in any view.
Display IPsec transform set
information.
display ipsec transform-set
[ transform-set-name ] [ | { begin |
exclude | include } regular-expression ]
Available in any view.
Display IPsec SA information.
display ipsec sa [ active | brief | policy
policy-name [ seq-number ] | remote
ip-address | standby ] [ | { begin |
exclude | include } regular-expression ]
Available in any view.
Display IPsec packet statistics.
display ipsec statistics [ tunnel-id integer ]
[ | { begin | exclude | include }
regular-expression ]
Available in any view.
Display IPsec tunnel information.
display ipsec tunnel [ active | standby ]
[ | { begin | exclude | include }
regular-expression ]
Available in any view.
Clear SAs.
reset ipsec sa [ active | parameters
dest-address protocol spi | policy
policy-name [ seq-number ] | remote
ip-address | standby ]
Available in user view.
Clear IPsec statistics.
reset ipsec statistics
Available in user view.