User's Manual

Table Of Contents
Fortress ES-Series CLI Guide: Network Security, Authentication and Auditing
131
Legacy
- AES-128-CBC, AES-256-CBC
Specify a time- and/or data-limited lifespan at the end of which
a new IKE transaction must be negotiated to establish new
IPsec SAs for the connection and/or a time-limited lifespan for
Phase 1 ISAKMP-authenticated SAs:
NOTE: If both
IPsec SA limits are
set to positive values,
both apply, and which-
ever condition occurs
first will cause the SA to
expire.
IPsec SA lifetime in minutes (
-
salifeMinutes) from 1 to
71,582,788 to determine how long the SA will be used
before it expires, or specify
0 (zero) to impose no time limit.
The default is
240 minutes (4 hours).
IPsec SA lifetime in kilobytes (
-
salifeKB) from 1 to
4,294,967,295 to determine how much data will pass on
the SA before it expires, or specify
0 (zero) to impose no
data limit. The default is
0
(zero), unlimited data.
ISAKMP SA lifetime in minutes (
-isakmplifeMinutes
) from
1 to 71,582,788 to determine how long the ISAKMP-
authenticated SA will be used before it expires, or specify
0
(zero) to impose no time limit. The default is
1440
minutes
(24 hours).
CAUTION:
If you
disable IPsec when
the function is in use, all
IKE and IPsec SAs will
be immediately termi-
nated, configured SPD
entries will be disabled,
and IPsec traffic will
cease to be sent or
received on any inter-
face.
Indicate whether the IPsec Certificate Revocation List (CRL)
function is enabled (
y) or disabled (n). When the IPsec CRL is
enabled, peer certificate chains are traced back to a trusted
root certificate and each certificate's serial number is checked
against the contents of the issuing authority’s CRL to verify that
none of the certificates in the chain have been revoked, as
described in RFC 3280.
Specify which
IKEversion will be used to initiate SAs.
You must be logged on to an
administrator
-level account to
change configuration settings (refer to Section 2.2).
View current IPsec parameters with
show ipsec:
# show ipsec
IPsec is disabled.
IPsec crypto suites: SuiteB256,SuiteB128
ISAKMP SA lifetime 1440 minutes
SA lifetime 240 minutes, unlimited KB
CRL checking is disabled.
IKE version 2
No key pair used for IPsec authentication