Crypto Global Domain Ipsec Security-Association Lifetime - Cisco MDS 9124 - Fabric Switch Reference

Cisco mds 9000 family command reference - cisco mds san-os release 3.0(1) through 3.3(1a) (ol-16217-01, april 2008)
Hide thumbs Also See for Cisco MDS 9124 - Fabric Switch:
Table of Contents

Advertisement

crypto global domain ipsec security-association lifetime

S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
crypto global domain ipsec security-association lifetime
To configure global parameters for IPsec, use the crypto global domain ipsec security-association
lifetime command. To revert to the default, use the no form of the command.
Syntax Description
gigabytes number
kilobytes number
megabytes number
seconds number
Defaults
450 gigabytes and 3600 seconds
Command Modes
Configuration mode.
Command History
Release
2.0(x)
Usage Guidelines
To use this command, IPsec must be enabled using the crypto ipsec enable command.
The global security association lifetime value can be overridden for individual IPsec crypto maps using
the set command in IPsec crypto map configuration submode.
Examples
The following example shows how to configure the system default before the IPsec.
switch# config terminal
switch(config)# crypto global domain ipsec security-association lifetime gigabytes 500
Related Commands
Command
crypto ipsec enable
set (IPsec crypto map
configuration submode)
show crypto global domain ipsec Displays the global attributes for IPsec.
Cisco MDS 9000 Family Command Reference
4-130
crypto global domain ipsec security-association lifetime {gigabytes number | kilobytes number |
megabytes number | seconds number}
no crypto global domain ipsec security-association lifetime {gigabytes | kilobytes | megabytes
| seconds}
Specifies a volume-based key duration in gigabytes. The range is 1 to 4095.
Specifies a volume-based key duration in kilobytes. The range is 2560 to
2147483647.
Specifies a volume-based key duration in megabytes. The range is 3 to
4193280.
Specifies a time-based key duration in seconds. The range is 120 to 86400.
Modification
This command was introduced.
Description
Enables IPsec.
Configures IPsec crypto map entry parameters.
Chapter 4
OL-16217-01, Cisco MDS SAN-OS Release 3.x
C Commands

Advertisement

Table of Contents
loading

Table of Contents