How to configure RAP IKE and IPSEC rekey lifetime using apboot mode?

Aruba Employee

Customer wants to change IKE and IPSEC lifetime for specific RAP.


We can set the RAP IKE and IPSEC rekey lifetime(secs) using the below environmental variables during apboot prompt.


apboot>setenv ikep1_lifetime <secs>  ----------> IKE Rekey Lifetime.
apboot>setenv ikep2_lifetime <secs>  ----------> IPSEC Rekey Lifetime.


Note#  The default hard-coded lifetime defined on RAP’s are  IKE- 28800 secs (8hrs) ;  IPSEC -7200 secs (2hrs).


commands to verify the config change:

(RAP) #show crypto isakmp sa peer <public ip>
(RAP) #show crypto ipsec sa peer <public ip>

Version history
Revision #:
2 of 2
Last update:
‎11-23-2015 02:33 PM
Updated by:
Labels (1)
Search Airheads
Showing results for 
Search instead for 
Did you mean: 
Is this a frequent problem?

Request an official Aruba knowledge base article to be written by our experts.