HP Comware 5 Debug Manual Vol 2

IPsec/IKE debugging commands
The output description tables in this document only contain fields and messages that require an
explanation.
IPsec debugging commands
debugging ipsec
Use debugging ipsec to enable IPsec debugging.
Use undo debugging ipsec to disable IPsec debugging.
Syntax
debugging ipsec { all | error | packet [ policy policy-name [ seq-number ] | parameters [ IPv6 ]
ip-address protocol spi-number ] | sa | synchronization }
undo debugging ipsec { all | error | packet [ policy policy-name [ seq-number ] | parameters [ IPv6 ]
ip-address protocol spi-number ] | sa | synchronization }
Default
IPsec debugging is disabled.
Views
User view
Default command level
1: Monitor level
Parameters
all: Specifies all types of IPsec debugging.
error: Specifies IPsec error debugging.
packet: Specifies IPsec packet debugging.
policy policy-name: Specifies an IPsec policy by its name. The policy-name argument is a string of 1 to
15 characters.
seq-number: Specifies an IPsec policy by its sequence number, in the range of 1 to 10000.
parameters: Specifies IPsec SA parameter debugging.
ipv6: Specifies an IPv6 address. Support for this keyword depends on the device model.
ip-address: Destination IP address.
protocol: Security protocol, AH o r ESP.
spi-number: Security parameters index (SPI), in the range of 256 to 4294967295.
sa: Specifies IPsec SA debugging.
synchronization: Specifies IPsec stateful failover debugging.
146