495
Default
The global IPsec SA idle timeout feature is disabled.
Views
System view
Predefined user roles
network-admin
Parameters
seconds
: Specifies the IPsec SA idle timeout in the range of 60 to 86400 seconds.
Usage guidelines
This feature applies only to IPsec SAs negotiated by IKE.
The IPsec SA idle timeout can also be configured in IPsec policy view, IPsec policy template view, or
IPsec profile view, which takes precedence over the global IPsec SA timeout.
Examples
# Enable the global IPsec SA idle timeout feature and set the IPsec SA idle timeout to 600 seconds.
<Sysname> system-view
[Sysname] ipsec sa idle-time 600
Related commands
display ipsec sa
sa idle-time
ipsec transform-set
Use
ipsec
transform-set
to create an IPsec transform set and enter its view, or enter the view of an
existing IPsec transform set.
Use
undo
ipsec
transform-set
to delete an IPsec transform set.
Syntax
ipsec
transform-set transform-set-name
undo ipsec transform-set transform-set-name
Default
No IPsec transform sets exist.
Views
System view
Predefined user roles
network-admin
Parameters
transform-set-name
: Specifies a name for the IPsec transform set, a case-insensitive string of 1 to 63
characters.
Usage guidelines
An IPsec transform set, part of an IPsec policy, defines the security parameters for IPsec SA
negotiation, including the security protocol, encryption algorithms, authentication algorithms, and
encapsulation mode.
Summary of Contents for FlexNetwork MSR Series
Page 1005: ...987 ...