crypto-map-ipsec-isakmp-instance
Defines the IPSec SA‘s (created by this auto site-to-site VPN tunnel or remote VPN client) settings
security-association [inactivity-timeout|level|lifetime]
security-association [inactivity-timeout <120-86400>|level perhost]
security-association lifetime [kilobytes <500-2147483646>|seconds <120-86400>]
security-association [inactivity-timeout <120-86400>|level perhost]
inactivity-timeout <120-86400> | Specifies an
inactivity period, in seconds, for this IPSec VPN SA. Once the set value is
exceeded, the association is timed out.
|
level perhost | Specifies the
granularity level for this IPSec VPN SA
|
security-association lifetime [kilobytes <500-2147483646>|seconds <120-86400>]
lifetime [kilobytes <500-2147483646>| seconds <120-86400>] | Defines the
IPSec SA‘s lifetime (in kilobytes and/or seconds). Values can be entered in
both kilobytes and seconds. Which ever limit is reached first, ends the
security association.
|
Site-to-site tunnel: nx9500-6C8809(config-device-B4-C7-99-6C-88-09-cryptomap-test#1)#security-association inactivity-timeout 200 nx9500-6C8809(config-device-B4-C7-99-6C-88-09-cryptomap-test#1)#security-association level perhost nx9500-6C8809(config-device-B4-C7-99-6C-88-09-cryptomap-test#1)#security-association lifetime kilobytes 250000 nx9500-6C8809(config-device-B4-C7-99-6C-88-09-cryptomap-test#1)#show context crypto map test 1 ipsec-isakmp security-association level perhost peer 1 ikev2 ikev2Peer1 local-endpoint-ip 192.168.13.10 pfs 5 security-association lifetime kilobytes 250000 security-association inactivity-timeout 200 ip nat crypto nx9500-6C8809(config-device-B4-C7-99-6C-88-09-cryptomap-test#1)# Remote VPN client: nx9500-6C8809(config-device-B4-C7-99-6C-88-09-cryptomap-test#2)#security-association lifetime seconds 10000 nx9500-6C8809(config-device-B4-C7-99-6C-88-09-cryptomap-test#2)#show context crypto map test 2 ipsec-isakmp dynamic peer 1 ikev1 RemoteIKEv1Peer1 local-endpoint-ip 157.235.204.62 pfs 14 security-association lifetime seconds 10000 remote-type none nx9500-6C8809(config-device-B4-C7-99-6C-88-09-cryptomap-test#2)#