R3303-HP 6600/HSR6600 Routers Security Configuration Guide

462
Configuring session log export
Session logs are exported in the form of flow logs.
To configure session log exporting:
Ste
p
Command
Remarks
1. Enter system view.
system-view N/A
2. Specify the flow log
version.
userlog flow export version version-number
Optional.
1.0 by default.
3. Specify the source IP
address for UDP
packets carrying flow
logs.
userlog flow export source-ip ip-address
Optional.
IP address of the interface
sending UDP packets by
default.
4. Specify the IP address
and UDP port number
of the flow log server.
userlog flow export slot slot-number
[ vpn-instance vpn-instance-name ] host
ip-address udp-port
Not specified by default.
5. Specify to export flow
logs to the information
center.
userlog flow syslog
Optional.
Flow logs are exported to the
flow log server by default.
For more information about flow log functions, see Network Management and Monitoring Configuration
Guide. For more information about flow log commands, see Network Management and Monitoring
Command Reference.
Displaying and maintaining session management
Task Command
Remarks
Display the session aging times for
application layer protocols.
display application aging-time [ |
{ begin | exclude | include }
regular-expression ]
Available in any view.
Display the session aging times in
different protocol states.
display session aging-time [ | { begin
| exclude | include }
regular-expression ]
Available in any view.
Display session count on the specified
card.
display session hardware slot
slot-number [ | { begin | exclude |
include } regular-expression ]
Available in any view.
This command is supported
only by the FIP600 card.
Display information about sessions
display session table [ slot
slot-number ] [ source-ip source-ip ]
[ destination-ip destination-ip ]
[verbose ] [ | { begin | exclude |
include } regular-expression ]
Available in any view.
This command is not
supported by the FIP600
card.