IP Security - Virtual Private Network
Left running head:
Chapter name (automatic)
834
Beta Beta
OmniAccess 5740 Unified Services Gateway CLI Configuration Guide
Alcatel-Lucent
T
O CONFIGURE IKE LIFETIME
Note: Default IKE lifetime = 86400 seconds.
E
XAMPLE
ALU(config-crypto-ike-policy-P1)# lifetime seconds 4096
ALU(config-crypto-ike-policy-P1)# no lifetime seconds
T
O CONFIGURE PFS (PERFECT FORWARD SECRECY) GROUP
EXAMPLE
ALU(config-crypto-ike-policy-P1)# pfs group1
ALU(config-crypto-ike-policy-P1)# no pfs
Command (in IKE Policy CM) Description
lifetime seconds <540-86400> This command is used to configure a
IKE lifetime.
no lifetime seconds The ‘no’ command resets the IKE
lifetime to its default.
Command (in IKE Policy CM) Description
pfs {group1|group2|group5} This command is used to configure a
PFS group.
Note: If the PFS group is not
explicitly configured,
group2 is used as the
default PFS.
no pfs The ‘no’ command resets the PFS
group to default.