How to configure RAP IKE and IPSEC rekey lifetime using apboot mode?

Aruba Employee
Requirement:

Customer wants to change IKE and IPSEC lifetime for specific RAP.



Solution:

We can set the RAP IKE and IPSEC rekey lifetime(secs) using the below environmental variables during apboot prompt.



Configuration:

apboot>setenv ikep1_lifetime <secs>  ----------> IKE Rekey Lifetime.
apboot>setenv ikep2_lifetime <secs>  ----------> IPSEC Rekey Lifetime.

 

Note#  The default hard-coded lifetime defined on RAP’s are  IKE- 28800 secs (8hrs) ;  IPSEC -7200 secs (2hrs).



Verification

commands to verify the config change:

(RAP) #show crypto isakmp sa peer <public ip>
(RAP) #show crypto ipsec sa peer <public ip>

Version history
Revision #:
2 of 2
Last update:
‎11-23-2015 02:33 PM
Updated by:
 
Labels (1)
Contributors
Search Airheads
cancel
Showing results for 
Search instead for 
Did you mean: