![Black Box ET0010A Скачать руководство пользователя страница 151](http://html1.mh-extra.com/html/black-box/et0010a/et0010a_cli-user-manual_2763784151.webp)
Command Reference
152
ETEP CLI User Guide
ipsec-sa-lifetime
Description
The
ipsec-sa-lifetime
command defines lifetime in seconds of the IPsec Phase 2 security association (SA)
in IKE policies on the management port.
User Type
Administrator
Hierarchy Level
ike-params-set mode (config > management-interface > ipsec-config > ike-parameters-set)
Syntax
ipsec-sa-lifetime {<lifetime>}
Attributes
lifetime -
SA lifetime in seconds. Valid values are 3600-31536000 seconds. The default is 28800 (8
hours).
Usage Guidelines
The IPsec SA lifetime is the interval after which an SA must be replaced with a new SA or terminated.
This is a global setting that will be used in all IKE encryption policies on the ETEP management port.
Related topic:
●
“Configuring Global Settings for IKE Negotiations” on page 79
Example
This example sets the IPsec Phase 2 SA lifetime to 7200 seconds (2 hours).
admin>
configure
config>
management-interface
man-if>
ipsec-config
ipsec-config>
ike-params-set
ike-params-set>
ipsec-sa-lifetime 7200
ipsec-sa-pfs
Description
The
ipsec-sa-pfs
command configures the Diffie-Hellman group ID used when perfect forward secrecy
(PFS) is enabled. This command applies to IKE policies on the management interface.
User Type
Administrator
Содержание ET0010A
Страница 7: ...8 ETEP CLI User Guide Contents...
Страница 15: ...Getting Started 16 ETEP CLI User Guide...
Страница 33: ...User Administration 34 ETEP CLI User Guide...
Страница 55: ...Configuring the ETEP 56 ETEP CLI User Guide...
Страница 97: ...Creating Policies 98 ETEP CLI User Guide...
Страница 101: ...Maintenance 102 ETEP CLI User Guide...
Страница 119: ...Troubleshooting 120 ETEP CLI User Guide...
Страница 123: ...FIPS 140 2 Level 2 Operation 124 ETEP CLI User Guide...
Страница 205: ...Command Reference 206 ETEP CLI User Guide...
Страница 211: ...Index 212 ETEP CLI User Guide...