![Enterasys X-Pedition XSR Cli Reference Manual Download Page 571](http://html1.mh-extra.com/html/enterasys/x-pedition-xsr/x-pedition-xsr_cli-reference-manual_2414758571.webp)
Crypto Transform Mode Commands
XSR CLI Reference Guide 14-117
Mode
Crypto
Transform
configuration:
XSR(cfg-crypto-tran)#
Example
This
example
selects
PFS
group
2
whenever
a
new
SA
is
negotiated
for
crypto
map
ACMEmap
:
XSR(config)#crypto map ACMEmap 7 ipsec-isakmp
XSR(config)#crypto ipsec transform-set t-set1 esp-3des esp-sha-hmac
XSR(cfg-crypto-tran)#set pfs group2
set security-association lifetime
This
command
sets
the
lifetime
interval
used
when
negotiating
IPSec
Security
Associations
(SAs).
Data
passing
through
the
XSR
is
encrypted
using
keys
generated
during
IKE
exchange.
The
lifetime
of
those
keys
may
be
defined
in
seconds
or
in
data
volume
which
was
encrypted
using
those
keys.
When
that
lifetime
expires
new
keys
are
generated
and
traffic
continues
to
be
passed
using
new
keys.
Syntax
set security-association lifetime
{
seconds
seconds
|
kilobytes
kilobytes
}
Syntax of the “no” Form
The
no
form
of
this
command
disables
the
specified
lifetime
metric.
It
does
not
reset
the
default:
no set security-association lifetime
{
seconds
|
kilobytes
}
Default
3600
seconds
with
no
limit
on
traffic
volume.
Mode
Crypto
Transform
configuration:
XSR(cfg-crypto-tran)#
Example
The
following
example
sets
the
SA
lifetime
to
7,200
KBytes
and
disables
the
seconds
parameter:
XSR(cfg-crypto-tran)#)#set security-association lifetime kilobytes 7200
XSR(cfg-crypto-tran)#)#no set security-association lifetime seconds
seconds
The
interval
an
SA
lives
before
expiring,
ranging
from
300
to
86,400,000
seconds.
kilobytes
The
volume
of
traffic,
in
KBytes,
that
can
pass
between
IPSec
peers
using
a
given
SA
before
that
SA
expires,
ranging
from
1
MByte
to
1000
GBytes.
Summary of Contents for X-Pedition XSR
Page 1: ...X Pedition Security Router XSR CLI Reference Guide Version 7 6 P N 9033842 07...
Page 2: ......
Page 10: ...viii...
Page 14: ...xii...
Page 134: ...Bootrom Monitor Mode Commands 3 128 Configuring the XSR Platform...
Page 278: ...VRRP Clear and Show Commands 5 202 Configuring the Internet Protocol...
Page 352: ...IGMP Clear and Show Commands 7 104 Configuring IP Multicast...
Page 406: ...Multilink Show Commands 8 136 Configuring the Point to Point Protocol...
Page 436: ...Frame Relay Clear and Show Commands 9 112 Configuring Frame Relay...
Page 460: ...Dialer Watch Commands 10 106 Configuring the Dialer Interface...