Enterasys Networks XSR CLI Router User Manual


 
Remote Peer ISAKMP Protocol Policy Mode Commands
XSR CLI Reference Guide 14-99
lifetime
ThiscommandspecifiesthelifetimeofanIKESecurityAssociation(SA)foragivenIKEproposal
(policy).
Syntax
lifetime seconds
Syntax of the “no” Form
Thenoformofthiscommandresetstothedefaultvalue:
no lifetime
Default
28,800seconds(8hours)
Mode
ISAKMPprotocolpolicyconfiguration:XSR(config-isakmp)#
Example
ThefollowingexamplesetstheIKESAlifetimeat8hoursforACMEproposal:
XSR(config)#crypto isakmp proposal ACMEproposal
XSR(config-isakmp)#lifetime 28800
Remote Peer ISAKMP Protocol Policy Mode Commands
crypto isakmp peer
Thiscommandconfigurestheremotepeer’sIPaddressand/orsubnetandacquiresISAKMP
configurationmode.ThefollowingsubcommandscanbeenteredatISAKMPPeermode:
config-mode setsthelocalIKEModeconfiguration,thedefactostandardtoassignIP
addresseswithinIKE.Refertopage14100forthecommanddefinition.
exchange-mode setsIKEtomainoraggressiveexchangemode.Refertopage14101forthe
commanddefinition.
nat-traversal setstheIKEandIPSecNAT(NetworkAddressTranslation)traversalmode.
Refertopage14102forthecommanddefinition.
proposal attachesIKEpoliciestoaremotepeer.Refertopage14102forthecommand
definition.
user-iddefinestheidentityinformation tobeusedduringaggressiveIKEPhase1
negotiation.Refertopage14103forthecommanddefinition.
seconds
Theinterval,inseconds,eachSAexistsbeforeexpiring.