< Home

Verifying the Configuration of IPSec Tunnel Establishment

Prerequisites

The configurations of the ACL-based IPSec tunnel are complete.

Procedure

  • Run the display ipsec proposal [ brief | name proposal-name ] or display ipsec proposal [ brief | name proposal-name ] ctrl-plane command to check IPSec proposal information.
  • Run the display ipsec policy [ brief | name policy-name [seq-number ] ] or display ipsec policy [ brief | name policy-name [ seq-number ] ] ctrl-plane command to check IPSec policy information.
  • Run the display ipsec policy-template [ brief | name policy-template-name [ seq-number ] ] or display ipsec policy-template [ brief | name policy-template-name [ seq-number ] ] ctrl-plane command to check IPSec policy template information.
  • Run the display ipsec sa [ [ brief ] [ slot slot-id cpu cpu-id ] | duration | policy policy-name [ seq-number ] | profile profile-name | remote { ipv4-address | ipv6-address } ] command to check IPSec SA information about the current system.
  • Run the display ipsec sa [ [ brief ] [ slot slot-id cpu cpu-id ] | policy policy-name [ seq-number ] | profile profile-name | remote { ipv4-address | ipv6-address } ] { active | standby } command to check IPSec SA information about the current system.
  • Run the display ipsec sa [ brief ] [ slot slot-id cpu cpu-id ] [ all-systems | vsys vsys-name ] [ active | standby ] command to check IPSec SA information about all systems including the root system and virtual system.
  • Run the display ipsec global config command to check global IPSec configuration.
  • If an IPSec tunnel is established in IKE negotiation mode, check the IKE configuration. See Verifying the IKE Configuration.
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic