HP Comware 5 Debug Manual Vol 2
Field
Description
finalize exchange
The IKE module was performing the final exchange of
IPsec packets.
exchange release
The IKE module was releasing the data structure for
the exchange.
Table 10 describes output fields and messages for the debugging ike packet command.
Table 121 Output from the debugging ike packet command
Field
Description
message alloc Memory allocated for messages.
ICOOKIE: Cookie of the initiator.
RCOOKIE: Cookie of the responder.
message parse payloads Message payload parsing.
NO: number The sequence number of the proposal is number.
PROTO: type The protocol type of the IP packet is type.
SPI_SZ: size Length of the SPI is size.
NTRANSFORMS: num Number of transform sets.
ID: id
ID of the transform set, the protocol number that the
transform set uses.
Attribute HASH_ALGORITHM : Hash algorithm for authentication.
Attribute AUTHENTICATION_METHOD :
Authentication method. It can be pre-shared key or
RSA signature.
Examples
# Enable all IKE debugging. Output similar to the following example is generated when you use the ping
-c 1 1.1.1.2 command to trigger IPsec SA establishment under the following conditions:
•
IPsec and IKE are configured on the device.
•
An IKE-based policy is configured.
•
An IPsec proposal using the default settings is specified for the policy.
•
The local gateway address is 1.1.1.1, and the peer gateway address is 1.1.1.2.
•
IKE aggressive mode is used at the local end.
<Sysname> debugging ike all
<Sysname> ping -c 1 1.1.1.2
*Mar 27 14:31:20:276 2007 Sysname IKE/7/DEBUG:transport reference: transport 7e6e884 now
has 2 references
*Mar 27 14:31:20:276 2007 Sysname IKE/7/DEBUG:transport reference: transport 7e6e744 now
has 2 references
*Mar 27 14:31:20:276 2007 Sysname IKE/7/DEBUG:release transport: transport 7e6e884 had
2 references
*Mar 27 14:31:20:276 2007 Sysname IKE/7/DEBUG:release transport: transport 7e6e744 had
2 references
*Mar 27 14:31:20:277 2007 Sysname IKE/7/DEBUG:Read message: message:
155