Controller Based WLANs

How to configure RAP IKE and IPSEC rekey lifetime using apboot mode?

by ‎11-23-2015 02:32 PM - edited ‎11-23-2015 02:33 PM

Customer wants to change IKE and IPSEC lifetime for specific RAP.


We can set the RAP IKE and IPSEC rekey lifetime(secs) using the below environmental variables during apboot prompt.


apboot>setenv ikep1_lifetime <secs>  ----------> IKE Rekey Lifetime.
apboot>setenv ikep2_lifetime <secs>  ----------> IPSEC Rekey Lifetime.


Note#  The default hard-coded lifetime defined on RAP’s are  IKE- 28800 secs (8hrs) ;  IPSEC -7200 secs (2hrs).


commands to verify the config change:

(RAP) #show crypto isakmp sa peer <public ip>
(RAP) #show crypto ipsec sa peer <public ip>

Search Airheads
Showing results for 
Search instead for 
Did you mean: 
Is this a frequent problem?

Request an official Aruba knowledge base article to be written by our experts.