< Home

ipsec flow-overlap check enable

Function

The ipsec flow-overlap check enable command enables detection of overlapping IPSec flows.

The undo ipsec flow-overlap check enable command disables detection of overlapping IPSec flows.

By default, detection of overlapping IPSec flows is disabled.

Format

ipsec flow-overlap check enable

undo ipsec flow-overlap check enable

Parameters

None

Views

System view

Default Level

2: Configuration level

Usage Guidelines

Application Scenarios

In an LTE IPSec scenario, new base stations are usually added during network upgrade and capacity expansion, and the firewall needs to interconnect with these new base stations. In this case, you can enable detection of overlapping IPSec flows so that the device can detect whether to-be-encrypted data flows generated by the new tunnel overlap with existing ones after IKE negotiation. If no, the new tunnel is successfully established. If yes, the new tunnel fails to be established, and the device sends an alarm (IPSEC/4/IPSECTUNNELSTOP) on to-be-encrypted data flow overlapping. This requires you analyze the device networking, and plan and deliver more reasonable ACL configurations.

Precautions

  • This function affects the device performance. You are advised to disable this function when the network operation is stable (without such operations as upgrade or capacity expansion).
  • Disable this function immediately after you complete such operations as upgrade or capacity expansion.

Example

# Enable detection of overlapping IPSec flows.

<sysname> system-view
[sysname] ipsec flow-overlap check enable
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >