3Com 3C13618 Command Reference Manual page 731

3com 3c13618: reference guide
Table of Contents

Advertisement

Description
Using the sa duration command, you can configure an individual SA lifetime of the
IPSec policy. Using the undo sa duration command, you can restore the use of the
global SA lifetime.
This command is applicable to the IPSec module of the operating system and crypto
card.
This command is used to set the individual SA lifetime for the IPSec policy. If the
individual lifetime is not set, then the global SA lifetime is adopted (refer to the ipsec
sa global-duration command).
The lifetime is only valid for the SA set up in the isakmp mode, and it has no lifetime
limitation to the SA set up in the manual mode, that is, the SA manually set up will
never be invalidated.
When IKE negotiates to set up a SA for IPSec, the lesser of the lifetime set locally
and that proposed by the peer is selected.
There are two types of lifetime: time-based and traffic-based lifetimes. No matter
which expires first, the SA will get invalid. Before the SA is about to get invalid, IKE
will set up a new SA for IPSec negotiation. So, a new SA is ready before the existing
one gets invalid.
Modifying the global lifetime will not affect an SA that has individually set up its own
lifetime. But the modified global lifetime will be used to set up a new SA in the future
IKE negotiation.
The secret key in the SA is invalidated when the SA is invalidated. A short lifetime will
make it difficult for the attacker to break the password, as the attacker can only get
less data encrypted by the same secret key. But a short lifetime will use more CPU
resource to set up a new SA.
For related commands, see ipsec policy (system view), ipsec policy (interface
view), security acl, tunnel local, tunnel remote, sa inbound/outbound, proposal,
ipsec sa global-duration.
Example
# Configure the SA lifetime for the IPSec policy to 2 hours, that is, 7200 seconds.
[3Com]ipsec policy shenzhen 100 isakmp
[3Com-ipsec-policy-shenzhen-100] sa duration time-based 7200
# Configure the SA lifetime for the IPSec policy to 20M bytes, that is, 20000 kilobytes.
[3Com]ipsec policy shenzhen 100 isakmp
[3Com-ipsec-policy-shenzhen-100]sa duration traffic-based 20000
Security
81

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

3c136123c136133c13616

Table of Contents