security-association

crypto-map-ipsec-manual-instance

Defines the lifetime (in kilobytes and/or seconds) of IPSec SAs created by this crypto map

Supported in the following platforms:

  • Access Points — AP505i, AP510i/e, AP560i/h
  • Service Platforms — NX5500, NX7500, NX9500, NX9600, VX9000

Syntax

security-association lifetime [kilobytes <500-2147483646>|seconds <120-86400>]

Parameters

security-association lifetime [kilobytes <500-2147483646>|seconds <120-86400>]
lifetime [kilobytes <500-2147483646>| seconds <120-86400>] Values can be entered in both kilobytes and seconds. Which ever limit is reached first, ends the security association.
  • kilobytes <500-2147483646> – Defines volume based key duration. Specify a value from 500 - 2147483646 bytes.
  • seconds <120-86400> – Defines time based key duration. Specify the time frame from 120 - 86400 seconds.
Note

Note

This command is not applicable to the ipsec-manual crypto map.

Example

nx9500-6C8809(config-profile-default-rfs4000-cryptomap-map2#2)#security-association lifetime seconds 123

nx9500-6C8809(config-profile-default-rfs4000-cryptomap-map2#2)#show context
 Command not applicable to this crypto map
nx9500-6C8809(config-profile-default-rfs4000-cryptomap-map2#2)#