HP-UX IPSec version A.02.00 manpages
ipsec_report(1M) ipsec_report(1M)
(IPSec Software Required)
------------------------
ISAKMP SA --------------------------
Sequence number: 1
Role: Responder
Local IP Address: 192.1.1.1
Remote IP Address: 192.1.1.3
Oakley Group: 2 Authentication Method: Pre-shared Keys
Authentication Algorithm: HMAC-MD5 Encryption Algorithm: AES128-CBC
Quick Modes Processed: 1 Lifetime (seconds): 28800
REPORT: ipsec_report -gateway active and ipsec_report -gateway configured
The
ipsec_report -gateway active
output shows entries for gateway IPSec policies that either
do not use a tunnel, or those that use a tunnel and the tunnel source address is an active IP interface (a
configured IP interface, up or down).
The output for
ipsec_report -gateway active
and ipsec_report -gateway configured
are the same, except for the header. The header
Active Gateway Policy Rule
precedes active
gateway policy entries and the header
Configured Gateway Policy Rule
precedes configured
gateway policy entries.
Gateway policy fields are defined as follows:
Rule Name
A character string used as the name of the policy rule.
ID
An integer used internally by IPSec to index the entries.
Cookie
An integer used to cross-reference entries in the cache and policy (rule) tables kept by the Pol-
icy daemon. Only active rules with SAs have a cookie value.
Src IP Address
The source end system IP address. (The source end-to-end address for outbound packets; the
destination end-to-end address for inbound packets.)
Prefix
The number of bits that must match when comparing IP addresses, beginning with the left-
most bit.
Port number
(This field is only present if the network protocol is TCP, UDP, or ALL.) The source or desti-
nation port number for the upper-layer protocol.
Dst IP Address
The destination end system IP address. (The destination end-to-end address for outbound
packets; the source end-to-end address for inbound packets.)
Network Protocol
The upper-layer protocol in the IP header.
Action
The action or transform applied to packets matching this entry. Possible values follow:
Forward
Forward the packet in clear text if no tunnel is specified, or forward through an IPSec
tunnel if a tunnel is specified.
Discard
Discard the packet.
FLAGS
(This field is not present if there are no flags configured.) The flags configured for this policy.
Possible flags are defined as follows:
MIPV6
indicates this policy is used for Mobile IPv6. HP-UX IPSec checks the Mobile IPv6 bind-
ing cache for routing information.
Tunnel Name
The name of the tunnel policy used with this host policy. This field is not present if no tunnel
is configured for this gateway policy.
50 Hewlett-Packard Company − 10 − HP-UX IPSec A.02.00