HP-UX IPSec version A.02.01 manpages

i
ipsec_admin(1M) ipsec_admin(1M)
(HP-UX IPSec Software Required)
NAME
ipsec_admin - HP-UX IPSec administration utility
SYNOPSIS
/usr/sbin/ipsec_admin -start
|st
[-audit
|
au audit_directory][
-auditlvl
|al
alert
|error
|warning|informative|debug]
[
-maxsize
|ms
max_audit_file_size]
[-traceon
|tn tcp
|
udp
|igmp|all]
[-spi_min
spi_min_value ][
-spi_max
spi_max_value ][
-spd_soft
spd_soft_limit][
-spd_hard
spd_hard_limit]
/usr/sbin/ipsec_admin -stop
|
sp
/usr/sbin/ipsec_admin -status
|
s
/usr/sbin/ipsec_admin -silentstatus
|ss
/usr/sbin/ipsec_admin -newpasswd
|
np password
/usr/sbin/ipsec_admin -audit
|
au
audit_directory
/usr/sbin/ipsec_admin -auditlvl
|al alert
|
error|
warning|informative|debug
/usr/sbin/ipsec_admin -maxsize
|
ms max_audit_file_size
/usr/sbin/ipsec_admin -traceon
|
tn tcp
|
udp|
igmp|all
/usr/sbin/ipsec_admin -traceoff
|tf tcp
|udp
|igmp|all
/usr/sbin/ipsec_admin
[-spd_soft spd_soft_limit]
/usr/sbin/ipsec_admin
[-spd_hard spd_hard_limit]
/usr/sbin/ipsec_admin -flushsa
|fa
/usr/sbin/ipsec_admin -flushp
|
fp
/usr/sbin/ipsec_admin -deletesa
|da
remote_ip_address
DESCRIPTION
ipsec_admin
is a utility for performing HP-UX IPSec administration tasks such as starting and stop-
ping the HP-UX IPSec subsystem and retrieving the status of the HP-UX IPSec subsystem. The HP-UX
IPSec subsystem includes the user-space key management daemon, audit daemon, policy daemon, and
the HP-UX IPSec kernel portion. You can also use
ipsec_admin to perform the following tasks:
Set the audit level.
Change the audit directory.
Set the maximum audit file size.
Get status on the HP-UX IPSec system.
Enable or disable Level 4 tracing for TCP, UDP or IGMP.
Delete the IKE and IPsec SAs for a give peer node.
Set the "soft" and "hard" limits for the size of the Security Policy Database (SPD).
Set the range from which HP-UX IPSec assigns Security Parameters Index (SPI) numbers for
inbound, dynamic key Security Associations (SAs). You can only change the SPI range when
you start HP-UX IPSec.
Change the HP-UX IPSec password. HP-UX IPSec does not have to be running when you
change the password.
ipsec_admin requires the optional HP-UX IPSec software.
You must have superuser capabilities to run
ipsec_admin.
In order to change the HP-UX IPSec password, you must provide the existing HP-UX IPSec password.
The HP-UX IPSec password must be entered from the keyboard; it cannot be redirected from a file.
Options
ipsec_admin recognizes the following command-line options and arguments:
-start|st
Starts the HP-UX IPSec subsystem, including all user-space daemons. If the configuration file
HP-UX IPSec A.02.01 1 Hewlett-Packard Company 1

Summary of content (64 pages)