HP MSR2000/3000/4000 Router Series Security Configuration Guide
264
If you set both time-based and traffic-based logging, the device outputs a session log when whichever is
reached. After outputting a session log, the device resets the traffic counter and restarts the interval for the
session.
If you enable session logging but specify neither the traffic-based nor the time-based type, the device
outputs a session log when a session entry is created or removed.
To configure session logging:
Ste
p
Command
Remarks
1. Enter system view.
system-view
N/A
2. (Optional.) Set a
time-based logging
type.
session log time-active time-value
By default, the device does not
output session logs.
3. (Optional.) Set a
traffic-based logging
type.
• Set the packet-based threshold:
session log packets-active packets-value
• Set the byte-based threshold:
session log bytes-active bytes-value
The device does not output
session logs based on the
packet-based or byte-based
threshold.
4. Enter interface view.
interface interface-type interface-number N/A
5. Enable session logging.
session log enable { ipv4 | ipv6 } [ acl
acl-number ] { inbound | outbound }
By default, session logging is
disabled.
Displaying and maintaining session management
Execute display commands in any view and reset commands in user view.
Task Command
Display the aging time for sessions of
different application layer protocols.
display session aging-time application
Display the aging time for sessions in
different protocol states.
display session aging-time state
Display session table entries
(MSR2000/MSR3000).
display session table { ipv4 | ipv6 } [ source-ip source-ip ]
[ destination-ip destination-ip ] [ verbose ]
Display session table entries (MSR4000).
display session table { ipv4 | ipv6 } [ slot slot-number ]
[ source-ip source-ip ] [ destination-ip destination-ip ] [ verbose ]
Display session statistics
(MSR2000/MSR3000).
display session statistics
Display session statistics (MSR4000). display session statistics [ slot slot-number ]
Display relation table entries
(MSR2000/MSR3000).
display session relation-table { ipv4 | ipv6 }
Display relation table entries (MSR4000). display session relation-table { ipv4 | ipv6 } [ slot slot-number ]
Clear IPv4 session table entries
(MSR2000/MSR3000).
reset session table ipv4 [ source-ip source-ip ] [ destination-ip
destination-ip ] [ protocol { dccp | icmp | raw-ip | sctp | tcp |
udp | udp-lite } ] [ source-port source-port ] [ destination-port
destination-port ] [ vpn-instance vpn-instance-name ]










