H3C S6550X-HI Series Command Reference Manual page 2267

Table of Contents

Advertisement

traffic-based kilobytes
Kilobytes. The value range is 1000 to 4294901760.
Usage guidelines
This command takes effect only when IKEv1 is used.
The IPsec SA soft lifetime buffers are used to determine the IPsec SA soft lifetimes.
If no IPsec SA soft lifetime buffers are configured, the system calculates a default time-based and a
default traffic-based IPsec SA soft lifetime.
If IPsec SA soft lifetime buffers are configured, the system calculates IPsec SA soft lifetimes as
follows:
Time-based IPsec SA soft lifetime = time-based IPsec SA lifetime – time-based IPsec SA soft
lifetime buffer.
If the calculated time-based IPsec SA soft lifetime is shorter than or equal to 20 seconds, the
system uses the default time-based IPsec SA soft lifetime.
Traffic-based IPsec SA soft lifetime = traffic-based IPsec SA lifetime – traffic-based IPsec SA
soft lifetime buffer.
If the calculated traffic-based IPsec SA soft lifetime is smaller than or equal to 1000 Kilobytes,
the system uses the default traffic-based IPsec SA soft lifetime.
You can also configure IPsec SA soft lifetime buffers in IPsec policy view or IPsec profile view. The
device prefers the IPsec SA lifetime buffers configured in IPsec policy view or IPsec profile view over
the global lifetime buffers configured in system view.
Examples
# Set the global time-based IPsec SA soft lifetime buffer to 600 seconds.
<Sysname> system-view
[Sysname] ipsec sa global-soft-duration buffer time-based 600
# Set the global traffic-based IPsec SA soft lifetime buffer to 10000 Kilobytes.
<Sysname> system-view
[Sysname] ipsec sa global-soft-duration buffer traffic-based 10000
Related commands
sa soft-duration buffer
ipsec sa idle-time
Use
ipsec sa idle-time
timeout. If no traffic matches an IPsec SA within the idle timeout interval, the IPsec SA is deleted.
Use
undo ipsec sa idle-time
Syntax
ipsec sa idle-time seconds
undo ipsec sa idle-time
Default
The global IPsec SA idle timeout feature is disabled.
Views
System view
Predefined user roles
network-admin
: Specifies the traffic-based IPsec SA soft lifetime buffer, in
to enable the global IPsec SA idle timeout feature and set the idle
to disable the global IPsec SA idle timeout feature.
42

Advertisement

Table of Contents
loading

Table of Contents