[Contents][Prev][Next][Index][Report an Error]

Clearing Security Associations

You can set up the router software to clear IKE or IPSec SAs automatically when the corresponding services PIC restarts or is taken offline. To configure this property, include the clear-ike-sas-on-pic-restart or clear-ipsec-sas-on-pic-restart statement at the [edit services ipsec-vpn] hierarchy level:

clear-ike-sas-on-pic-restart;
clear-ipsec-sas-on-pic-restart;

After you add this statement to the configuration, all the IKE or IPSec SAs corresponding to the tunnels in the PIC will be cleared when the PIC restarts or goes offline.


[Contents][Prev][Next][Index][Report an Error]