ike-lifetime

crypto-auto-ipsec-tunnel commands

Configures the IKE SA‘s key lifetime in seconds

The lifetime defines how long a connection (encryption/authentication keys) should last, from successful key negotiation to expiration. Two peers need not exactly agree on the lifetime, though if they do not, there is some clutter for a superseded connection on the peer defining the lifetime as longer.

Supported in the following platforms:

  • Access Points — AP505i, AP510i, AP510e, AP560i, AP6522, AP6562, AP7161, AP7502, AP7522, AP7532, AP7562, AP7602, AP7612, AP7622, AP763, AP7662, AP8163, AP8543, AP8533.
  • Service Platforms — NX5500, NX7500, NX9500, NX9600, VX9000

Syntax

ike-lifetime <600-86400>

Parameters

ike-lifetime <600-86400>
ike-lifetime <600-86400> Sets the IKE SA‘s key lifetime in seconds
  • <600-86400> – Specify a value fro m 600 - 86400 seconds. The default is 8600 seconds.

Example

rfs4000-229D58(config-profile-testRFS4000-crypto-auto-ipsec-secure)#ike-lifetime 800

rfs4000-229D58(config-profile-testRFS4000-crypto-auto-ipsec-secure)#show context crypto auto-ipsec-secure
  ike-lifetime 800
rfs4000-229D58(config-profile-testRFS4000-crypto-auto-ipsec-secure)#