Sa Duration; Snmp-Agent Trap Enable Ike - HPE FlexFabric 7900 Series Security Command Reference

Hide thumbs Also See for FlexFabric 7900 Series:
Table of Contents

Advertisement

Related commands

snmp-agent trap enable ike

sa duration

Use sa duration to set the IKE SA lifetime for an IKE proposal.
Use undo sa duration to restore the default.
Syntax
sa duration seconds
undo sa duration
Default
The IKE SA lifetime is 86400 seconds.
Views
IKE proposal view
Predefined user roles
network-admin
mdc-admin
Parameters
seconds: Specifies the IKE SA lifetime in seconds, in the range of 60 to 604800.
Usage guidelines
If the communicating peers are configured with different IKE SA lifetime settings, the smaller setting
takes effect.
Before an IKE SA expires, IKE negotiates a new SA. The new SA takes effect immediately after it is
negotiated. The old IKE SA will be cleared when it expires.
Examples
# Set the IKE SA lifetime to 600 seconds for IKE proposal 1.
<Sysname> system-view
[Sysname] ike proposal 1
[Sysname-ike-proposal-1] sa duration 600
Related commands
display ike proposal
snmp-agent trap enable ike
Use snmp-agent trap enable ike command to enable SNMP notifications for IKE.
Use undo snmp-agent trap enable ike to disable SNMP notifications for IKE.
Syntax
snmp-agent trap enable ike [ attr-not-support | auth-failure | cert-type-unsupport
cert-unavailable
invalid-id
|
proposal–delete | tunnel-start | tunnel-stop | unsupport-exch-type ] *
undo snmp-agent trap enable ike [ attr-not-support | auth-failure | cert-type-unsupport
cert-unavailable
decrypt-failure | encrypt-failure | global | invalid-cert-auth
|
invalid-proposal | invalid-protocol
decrypt-failure | encrypt-failure | global | invalid-cert-auth
|
invalid-sign
no-sa-failure | proposal-add |
|
|
242
|
invalid-cookie |
|
|
invalid-cookie |
|

Advertisement

Table of Contents
loading

Table of Contents