326
Parameters
name
: Specifies the name of the peer security gateway for IKE negotiation, a string of 1 to 32
characters.
Usage guidelines
If you configure the
id-type name
or
id-type user-fqdn
command on the initiator, the IKE
negotiation initiator sends its security gateway name as its ID for IKE negotiation, and the peer uses
the security gateway name configured with the
remote-name
command to authenticate the initiator.
Make sure the local gateway name matches the remote gateway name configured on the peer.
Related commands
•
id-type
•
local-name
•
ike
local-name
Examples
# Configure the remote security gateway name as
apple
for IKE peer peer1.
<Sysname> system-view
[Sysname] ike peer peer1
[Sysname-ike-peer-peer1] remote-name apple
reset ike sa
Use
reset ike sa
to clear IKE SAs.
Syntax
reset
ike
sa
[
connection-id
]
Views
User view
Default command level
2: System level
Parameters
connection-id
: Specifies the connection ID of the IKE SA to be cleared, in the range of 1 to
2000000000.
Usage guidelines
If you do not specify a connection ID, the command clears all ISAKMP SAs.
When you clear a local IPsec SA, its ISAKMP SA can transmit the Delete message to notify the
remote end to delete the paired IPsec SA. If the ISAKMP SA has been cleared, the local end cannot
notify the remote end to clear the paired IPsec SA, and you must manually clear the remote IPsec
SA.
Examples
# Clear the IKE SA that uses connection ID 2.
<Sysname> display ike sa
total phase-1 SAs: 1
connection-id peer flag phase doi
----------------------------------------------------------
1 202.38.0.2 RD|ST 1 IPSEC
2 202.38.0.2 RD|ST 2 IPSEC