Implementing IPSec Network Security on Cisco IOS XR Software
Command or Action
Step 3
crypto ipsec security-association replay disable
Example:
RP/0/0/CPU0:router(config)# crypto ipsec
security-association replay disable
Step 4
end
or
commit
Example:
RP/0/0/CPU0:router(config)# end
or
RP/0/0/CPU0:router(config)# commit
Disabling IPSec Replay Checking on a Crypto Profile
This task disables replay checking on a crypto profile.
SUMMARY STEPS
1.
2.
3.
4.
configure
crypto ipsec profile name
set security-association replay disable
end
or
commit
How to Implement General IPSec Configurations for IPSec Networks
Purpose
Disables checking globally.
Configure this command or the crypto ipsec
Note
security-association replay window-size
command. The two commands are not used
at the same time.
Saves configuration changes.
When you issue the end command, the system
•
prompts you to commit changes:
Uncommitted changes found, commit them
before exiting(yes/no/cancel)?
[cancel]:
–
Entering yes saves configuration changes to
the running configuration file, exits the
configuration session, and returns the
router to EXEC mode.
Entering no exits the configuration session
–
and returns the router to EXEC mode
without committing the configuration
changes.
Entering cancel leaves the router in the
–
current configuration session without
exiting or committing the configuration
changes.
Use the commit command to save the
•
configuration changes to the running
configuration file and remain within the
configuration session.
Cisco IOS XR System Security Configuration Guide
SC-117