Cisco CRS-1 - Carrier Routing System Router Configuration Manual page 136

Ios xr system security configuration guide
Hide thumbs Also See for CRS-1 - Carrier Routing System Router:
Table of Contents

Advertisement

How to Implement IKE Security Protocol Configurations for IPSec Networks
3.
4.
DETAILED STEPS
Command or Action
Step 1
configure
Example:
RP/0/RP0/CPU0:router# configure
Step 2
crypto isakmp call admission limit
{in-negotiation-sa number | sa number}
Example:
RP/0/RP0/CPU0:router(config)# crypto isakmp call
admission limit sa 25
Cisco IOS XR System Security Configuration Guide for the Cisco CRS-1 Router
SC-130
end
or
commit
show cyrpto isakmp call admission statistics
Implementing Internet Key Exchange Security Protocol on Cisco IOS XR Software
Purpose
Enters global configuration mode.
Specifies the maximum number of IKE SAs that the
router can establish before IKE begins rejecting new
SA requests.
Use the in-negotiation-sa keyword to specify
the maximum number of in-negotiation
(embryonic) IKE security associations (SAs)
that the router can establish before IKE begins
rejecting new SA requests. The range for the
number argument is from 1 to 100000.
Use the sa keyword to specify the maximum
number of active IKE SAs that the router can
establish. The range for the number argument is
from 1 to 100000.
OL-20382-01

Advertisement

Table of Contents
loading

Table of Contents