The reset ike sa command deletes the SA set up by IKE.
This command is supported only on the NetEngine 8000 F1A.
Parameter | Description | Value |
---|---|---|
slot slotnumber |
Deletes the IKE SA in a specified slot. |
The value is an integer that ranges from 0 to 32. |
speed speed |
Set delete speed. |
It is an integer that ranges from 1 to 200 (per second). |
connid |
Deletes the IKE SA by connection ID. |
It is an integer and ranges from 1 to 65535. |
remote remoteaddr |
Deletes the IKE SA by remote address. |
The value is in dotted decimal notation |
To re-configure the IPSec policy, you can clear IKE SAs. There are two types of IKE SAs established by IKE negotiation: IKE SAs in phase 1 and IKE SAs in phase 2. IKE SAs in phase 1 are used for IKE negotiation. Under the protection of these IKE SAs, IKE SAs in phase 2 are used to establish IPSec SAs that protect data flows.