cts sxp speaker hold-time
To configure the global hold-time period of a speaker network device in a Cisco TrustSec Security Group
Tag (SGT) Exchange Protocol version 4 (SXPv4) network, use the
cts sxp speaker hold-time
command in
global configuration mode. To remove the hold time from the speaker device, use the
no
form of this command.
cts sxp speaker hold-time minimum-period
no cts sxp speaker hold-time
Syntax Description
Minimum allowed hold time in seconds. The range is from 1 to 65534.
minimum-period
Command Default
The default hold time for a speaker device is 120 seconds.
Command Modes
Global configuration
Command History
Modification
Release
This command was introduced.
8.0(1)
Usage Guidelines
The Security Group Tag Exchange Protocol (SXP) uses a TCP-based, keepalive mechanism to determine if
a connection is live. SXPv4 adds an optional negotiated keepalive mechanism, the hold-time period, in order
to provide more predictable and timely detection of connection loss.
Hold time can be configured globally on a network device. This global configuration will apply the configuration
to all SXP connections configured on the device.
You may configure a hold-time period locally on a speaker device or a default of 120 seconds is used. This
is the shortest period of time a speaker is willing to send keepalive messages for keeping the connection active.
Any shorter hold-time period would require a faster keepalive rate than the rate the speaker is ready to support.
A value of 0xFFFF indicates that the keepalive mechanism is not used.
The hold-time negotiation between the speaker device and the listener device succeeds when the speaker
’
s
minimum acceptable hold time falls below or within the desirable hold-time range of the listener. (Use the
cts sxp listener hold-time
command to configure the hold time of the listener device.) If one end turns off
the keepalive mechanism, the other end should also turn it off to make the negotiation successful.
The negotiation fails when the speaker
’
s minimum acceptable hold-time is greater than the upper bound of
the listener
’
s hold-time range.
The selected hold-time period of a successful negotiation is the maximum of the speaker's minimum acceptable
hold time and the lower bound of the listener's hold-time range.
The speaker calculates the keepalive time to one-third of the selected hold time by default, unless a different
keepalive time is locally configured.
Cisco Nexus 7000 Series Security Command Reference
189
C Commands
cts sxp speaker hold-time
Содержание Nexus 7000 Series
Страница 2: ... Cisco Systems Inc All rights reserved ...
Страница 20: ...Cisco Nexus 7000 Series Security Command Reference xx Contents ...
Страница 62: ...Cisco Nexus 7000 Series Security Command Reference 36 A Commands aaa authentication rejected ...
Страница 78: ...Cisco Nexus 7000 Series Security Command Reference 52 A Commands aaa user default role ...
Страница 157: ...Cisco Nexus 7000 Series Security Command Reference 131 C Commands crypto ca import ...
Страница 172: ...Cisco Nexus 7000 Series Security Command Reference 146 C Commands cts role based sgt map ...
Страница 186: ...Cisco Nexus 7000 Series Security Command Reference 160 C Commands cts role based access list ...
Страница 190: ...Cisco Nexus 7000 Series Security Command Reference 164 C Commands cts role based detailed logging ...
Страница 256: ...dscp dscp Cisco Nexus 7000 Series Security Command Reference 230 D Commands deny IPv4 ...
Страница 271: ...protocol Cisco Nexus 7000 Series Security Command Reference 245 D Commands deny IPv6 ...
Страница 274: ...dscp dscp Cisco Nexus 7000 Series Security Command Reference 248 D Commands deny IPv6 ...
Страница 291: ...Cisco Nexus 7000 Series Security Command Reference 265 D Commands description identity policy ...
Страница 293: ...Cisco Nexus 7000 Series Security Command Reference 267 D Commands description user role ...
Страница 299: ...Cisco Nexus 7000 Series Security Command Reference 273 D Commands device role ...
Страница 313: ...Cisco Nexus 7000 Series Security Command Reference 287 E Commands enable Cert DN match ...
Страница 340: ...Cisco Nexus 7000 Series Security Command Reference 314 E Commands eq ...
Страница 344: ...Cisco Nexus 7000 Series Security Command Reference 318 F Commands feature cts ...
Страница 350: ...Cisco Nexus 7000 Series Security Command Reference 324 F Commands feature ldap ...
Страница 369: ...G Commands gt page 344 Cisco Nexus 7000 Series Security Command Reference 343 ...
Страница 372: ...Cisco Nexus 7000 Series Security Command Reference 346 G Commands gt ...
Страница 398: ...Cisco Nexus 7000 Series Security Command Reference 372 I Commands interface policy deny ...
Страница 454: ...Cisco Nexus 7000 Series Security Command Reference 428 I Commands ip udp relay subnet broadcast ...
Страница 470: ...Cisco Nexus 7000 Series Security Command Reference 444 I Commands ipv6 dhcp ldra attach policy interface ...
Страница 497: ...Cisco Nexus 7000 Series Security Command Reference 471 K Commands key config key ...
Страница 504: ...Cisco Nexus 7000 Series Security Command Reference 478 K Commands key string ...
Страница 518: ...Cisco Nexus 7000 Series Security Command Reference 492 L Commands It ...
Страница 536: ...Cisco Nexus 7000 Series Security Command Reference 510 M Commands monitor session ...
Страница 537: ...N Commands nac enable page 512 neq page 513 Cisco Nexus 7000 Series Security Command Reference 511 ...
Страница 543: ...Cisco Nexus 7000 Series Security Command Reference 517 O Commands object group identity policy ...
Страница 552: ...Cisco Nexus 7000 Series Security Command Reference 526 O Commands other config flag ...
Страница 569: ...dscp dscp Cisco Nexus 7000 Series Security Command Reference 543 P Commands permit IPv4 ...
Страница 584: ...protocol Cisco Nexus 7000 Series Security Command Reference 558 P Commands permit IPv6 ...
Страница 587: ...dscp dscp Cisco Nexus 7000 Series Security Command Reference 561 P Commands permit IPv6 ...
Страница 622: ...Cisco Nexus 7000 Series Security Command Reference 596 P Commands propagate sgt ...
Страница 664: ...Cisco Nexus 7000 Series Security Command Reference 638 R Commands rule ...
Страница 714: ...Cisco Nexus 7000 Series Security Command Reference 688 S Commands switchport port security violation ...
Страница 737: ...Cisco Nexus 7000 Series Security Command Reference 711 Show Commands show arp access lists ...
Страница 841: ...Cisco Nexus 7000 Series Security Command Reference 815 Show Commands show ipv6 dhcp ldra ...
Страница 992: ...Cisco Nexus 7000 Series Security Command Reference 966 T Commands trustedCert ...
Страница 1015: ...Cisco Nexus 7000 Series Security Command Reference 989 V Commands vlan policy deny ...
Страница 1017: ...Cisco Nexus 7000 Series Security Command Reference 991 V Commands vrf policy deny ...
Страница 1018: ...Cisco Nexus 7000 Series Security Command Reference 992 V Commands vrf policy deny ...