R3102-R3103-HP 6600/HSR6600 Routers Security Command Reference

289
Field Descri
p
tion
can't find SA Number of packets dropped due to finding no security association.
queue is full Number of packets dropped due to full queues.
authentication has failed Number of packets dropped due to authentication failure.
wrong length Number of packets dropped due to wrong packet length.
replay packet Number of packets replayed.
packet too long Number of packets dropped due to excessive packet length.
wrong SA Number of packets dropped due to improper SA.
decrypt/encrypt failed
Number of packets dropped due to decryption or encryption
failure.
Related commands
reset ipsec statistics
display ipsec transform-set
Use display ipsec transform-set to display information about IPsec transform sets.
Syntax
display ipsec transform-set [ transform-set-name ] [ | { begin | exclude | include } regular-expression ]
Views
Any view
Default command level
1: Monitor level
Parameters
transform-set-name: Name of an IPsec transform set, a string of 1 to 32 characters. If you do not specify
an IPsec transform set, the command displays information about all IPsec transform sets.
|: Filters command output by specifying a regular expression. For more information about regular
expressions, see Fundamentals Configuration Guide.
begin: Displays the first line that matches the specified regular expression and all lines that follow.
exclude: Displays all lines that do not match the specified regular expression.
include: Displays all lines that match the specified regular expression.
regular-expression: Specifies a regular expression, a case-sensitive string of 1 to 256 characters.
Usage guidelines
If you do not specify any parameters, the command displays information about all IPsec transform sets.
Examples
# Display information about all IPsec transform sets.
<Sysname> display ipsec transform-set
IPsec transform-set name: tran1
encapsulation mode: tunnel