Remote Peer ISAKMP Protocol Policy Mode Commands
XSR CLI Reference Guide 14-99
lifetime
ThiscommandspecifiesthelifetimeofanIKESecurityAssociation(SA)foragivenIKEproposal
(policy).
Syntax
lifetime seconds
Syntax of the “no” Form
Thenoformofthiscommandresetstothedefaultvalue:
no lifetime
Default
28,800seconds(8hours)
Mode
ISAKMPprotocolpolicyconfiguration:XSR(config-isakmp)#
Example
ThefollowingexamplesetstheIKESAlifetimeat8hoursforACMEproposal:
XSR(config)#crypto isakmp proposal ACMEproposal
XSR(config-isakmp)#lifetime 28800
Remote Peer ISAKMP Protocol Policy Mode Commands
crypto isakmp peer
Thiscommandconfigurestheremotepeer’sIPaddressand/orsubnetandacquiresISAKMP
configurationmode.Thefollowingsub‐commandscanbeenteredatISAKMPPeermode:
•
config-mode setsthelocalIKEModeconfiguration,thedefactostandardtoassignIP
addresseswithinIKE.Refertopage14‐100forthecommanddefinition.
•
exchange-mode setsIKEtomainoraggressiveexchangemode.Refertopage14‐101forthe
commanddefinition.
•
nat-traversal setstheIKEandIPSecNAT(NetworkAddressTranslation)traversalmode.
Refertopage14‐102forthecommanddefinition.
•
proposal attachesIKEpoliciestoaremotepeer.Refertopage14‐102forthecommand
definition.
•
user-iddefinestheidentityinformation tobeusedduringaggressiveIKEPhase1
negotiation.Refertopage14‐103forthecommanddefinition.
seconds
Theinterval,inseconds,eachSAexistsbeforeexpiring.