Concept Guide

Table Of Contents
1447| show datapath Dell Networking W-Series ArubaOS 6.5.x| Reference Guide
--------------------------
Crypto Accelerator Present
Crypto Cores In Use 1
Crypto Cores Total 4
Crypto Requests Total 16
Crypto Requests Queued 0
Crypto Requests Failed 0
Crypto Timeouts 0
Crypto NoCoreFree 0
Crypto BadNPlus 0
Crypto SendNPlusFailed 0
IPSec Encryption Failures 0
IPSec Decryption Failures 0
IPSec Decryption Loops 0
IPSec Decryption BufFail 0
IPSec Decr SPI(client) ERR 0
IPSec Decrypt SA Not Ready 0
IPSec Frag Failures 0
IPSec Bad Pad Length 0
IPSec Invalid TCP Index 0
IPSec Invalid Length 0
IPSec Invalid Head-Room 0
IPSec Invalid Protocol 0
PPTP Encryption Failures 0
PPTP Decryption Failures 0
WEP Encryption Failures 0
WEP Decryption Failures 0
WEP No Key (not serious) 0
TKIP Encryptions 0
TKIP Encryption Failures 0
TKIP Decryptions 0
TKIP Decryption Failures 0
TKIP MIC Failures 0
TKIP Decrypt Bad Counter 0
TKIP P1Key Not Ready 0
...
The following parameters appear in the output of the show datapath crypto counters command, and are
useful for debugging purposes.
Parameter Description
Crypto BadNPlus
Indicates a queue overrun in the output of the encryption circuit.
Crypto SendNPlusFailed
Indicates a queue overrun in the input of the encryption circuit.
IPSec Frag Failures
This counter increments when the AP detects a failure to fragment a frame
before or after IPsec encryption.
IPSec Invalid Length
The inbound IPsec frame length is verified before and after decryption. If
the frame length is found to be incorrect , this counter is incremented.
IKE Rate
When the controller firewall receives a UDP packet, it determines if the
packet is destined for an IKE (500) or IPSEC_NATT (4500) port. This counter
increments when the AP receives an initial IKE packet that has an 8-byte
responder cookie defined all 0s.
Example of the show datapath compression command output