340
reverse-route tag
Use reverse-route tag to set a route tag for the static routes created by IPsec RRI. This tag helps in
implementing flexible route control through routing policies.
Use undo reverse-route tag to restore the default.
Syntax
reverse-route tag tag-value
undo reverse-route tag
Default
The tag value is 0 for the static routes created by IPsec RRI.
Views
IPsec policy view, IPsec policy template view
Predefined user roles
network-admin
Parameters
tag-value: Sets a tag value. The value range is 1 to 4294967295.
Usage guidelines
When you change this tag value in an IPsec policy, the device deletes all IPsec SAs created by this IPsec
policy, and all associated static routes.
Examples
# Set the tag value to 50 for the static routes created by IPsec RRI.
<Sysname>system-view
[Sysname] ipsec policy 1 1 isakmp
[Sysname-ipsec-policy-isakmp-1-1] reverse-route tag 50
Related commands
• ipsec policy
• ipsec policy-template
sa duration
Use sa duration to set an SA lifetime for an IPsec policy or IPsec policy template.
Use undo sa duration to remove the SA lifetime.
Syntax
sa duration { time-based seconds | traffic-based kilobytes }
undo sa duration { time-based | traffic-based }
Default
The SA lifetime of an IPsec policy or an IPsec policy template is the current global SA lifetime.
Views
IPsec policy view, IPsec policy template view