< Home

(Optional) Disabling the Function of Instructing the Peer Device to Delete the Old Child SA

Context

In an IKEv2 scenario, when the local device deletes the child SA and initiates IKEv2 negotiation to the peer device again, the default negotiation message carries the IKEV2_NOTIFY_DELETE_OLD_CHILDSA payload, instructing the peer device to delete the old child SA. If the peer device does not support the processing of this payload, IKEv2 negotiation between the two ends fails. To prevent this problem, disable the local device from instructing the peer device to delete the old child SA so that the IKEv2 negotiation message does not carry this payload.

Procedure

  1. Run system-view

    The system view is displayed.

  2. Run undo ikev2 delete old child-sa enable

    The function of instructing the peer device to delete the old child SA is disabled.

    By default, the function of instructing the peer device to delete the old child SA is enabled.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >