Cisco IOS XR Configuration Manual page 63

System security configuration guide
Hide thumbs Also See for IOS XR:
Table of Contents

Advertisement

Implementing Internet Key Exchange Security Protocol on Cisco IOS XR Software
3.
4.
DETAILED STEPS
Command or Action
Step 1
configure
Example:
RP/0/RP0/CPU0:router# configure
Step 2
crypto isakmp call admission limit
{in-negotiation-sa number | sa number }
Example:
RP/0/RP0/CPU0:router(config)# crypto isakmp call
admission limit sa 25
end
or
commit
show crypto isakmp call admission statistics
How to Implement IKE Security Protocol Configurations for IPSec Networks
Purpose
Enters global configuration mode.
Specifies the maximum number of IKE SAs that the
router can establish before IKE begins rejecting new
SA requests.
Use the in-negotiation-sa keyword to specify
the maximum number of in-negotiation
(embryonic) IKE security associations (SAs)
that the router can establish before IKE begins
rejecting new SA requests. The range for the
number argument is from 1 to 100000.
Use the sa keyword to specify the maximum
number of active IKE SAs that the router can
establish. The range for the number argument is
from 1 to 100000.
Cisco IOS XR System Security Configuration Guide
SC-51

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ios xr 3.5

Table of Contents