Df bit commands, Df bit commands -137 – Enterasys Networks X-Pedition XSR CLI User Manual

Page 591

Advertising
background image

DF Bit Commands

XSR CLI Reference Guide 14-137

10.120.122.22
10.120.122.24
10.120.122.25
10.120.122.26
10.120.122.28
10.120.122.31
10.120.122.32
Inuse addresses:
10.120.122.10
10.120.122.21
10.120.122.23
10.120.122.27
10.120.122.29
10.120.122.30
10.120.122.34
Excluded addresses:
Reserved addresses:
10.120.122.0
10.120.122.4

Parameter Description

DF Bit Commands

crypto ipsec df-bit (Global configuration)

This command sets the DF bit for the encapsulating header in VPN Tunnel Mode to all interfaces.

The clear setting for the DF bit should be used for encapsulating Tunnel Mode IPSec traffic when 
you can transmit packets larger than the available MTU size or you do not know the available 
MTU size.

Syntax

crypto ipsec df-bit {clear | set | copy}

Pool

Name of the IP pool.

Subnet

Mask of the IP pool.

Mask

IP address subnetwork of the IP pool.

Free

Sum of unused IP addresses within the pool.

In use

Sum of occupied IP addresses within the pool.

Excluded

Sum of IP addresses barred from use within the pool.

Reserved

Sum of IP addresses set aside within the pool, such as the initial address 
192.168.57.0 within the 192.168.57.256 range.

clear

XSR will clear the DF bit from the outer IP header; the router may 
fragment the packet to add IPSec encapsulation.

set

XSR will set the DF bit in the outer IP header but the router may 
fragment the packet if the original packet had the DF bit cleared.

Advertising