Command Reference Guide
240 ● reset ipsec sa 3Com Router 5000 Family and Router 6000 Family
Command Reference
Delete an SA whose remote IP address is 10.1.1.2, security protocol is AH, and SPI is
10000.
<3Com> reset ipsec sa parameters 10.1.1.2 ah 10000
View This command can be used in the following views:
■ User view
Description An SA is uniquely identified by a triplet of IP address, security protocol and SPI. A SA
can be set up either manually or through Internet Key Exchange (IKE) negotiation.
If an SA set up manually is deleted, the system will automatically set up a new SA
according to the parameter manually set up.
If a packet re-triggers IKE negotiation after an SA set up through IKE negotiation is
deleted, IKE will reestablish an SA through negotiation.
The keyword parameters will take effect only after the spi of the outbound SA is
defined. Because SAs appear in pairs, the inbound SA will also be deleted after the
outbound SA is deleted.
Related Command display ipsec sa