Brocade Mobility RFS Controller CLI Reference Guide (Supporting software release 5.5.0.0 and later) User Manual

Page 609

Advertising
background image

596

Brocade Mobility RFS Controller CLI Reference Guide

53-1003098-01

7

write Write running configuration to memory or terminal

rfs7000-37FABE(config-profile-test-ikev2-policy-ikev2-testpolicy)#

NOTE

IKEv2 being an improved version of the original IKEv1 design, is recommended in most
deployments. IKEv2 provides enhanced cryptographic mechanisms, NAT and firewall traversal,
attack resistance etc.

The following table summarizes crypto IKEv1/iKEv2 commands.

dpd-keepalive

crypto-ikev1/ikev2-policy commands

Sets the DPD keep-alive packet interval

Supported in the following platforms:

Access Points — Brocade Mobility 650 Access Point, Brocade Mobility 6511 Access Point,
Brocade Mobility 1220 Access Point, Brocade Mobility 71XX Access Point, Brocade
Mobility 1240 Access Point

Wireless Controllers — Brocade Mobility RFS4000, Brocade Mobility RFS6000, Brocade
Mobility RFS7000

Service Platforms — Brocade Mobility RFS9510

Syntax:

dpd-keepalive <10-3600>

Parameters

dpd-keepalive <10-3600>

Example

rfs7000-37FABE(config-profile-default-rfs7000-ikev1-policy-ikev1-testpolicy)#

dpd-keepalive 11

rfs7000-37FABE(config-profile-default-rfs7000-ikev1-policy-testpolicy)#show

context

crypto ikev1 policy testpolicy

Command

Description

Reference

dpd-keepalive

Sets DPD keep alive packet interval

page 596

dpd-retries

Sets the maximum number of attempts for sending Dead-Peer-Detection (DPD) keep alive
packets (applicable only to the IKEv1 policy)

page 7-597

isakmp-proposal

Configures ISAKMP proposals

page 7-597

lifetime

Specifies how long an IKE SA is valid before it expires

page 7-598

mode

Sets the mode of the tunnels (applicable only to the IKEv1 policy)

page 7-599

no

Negates a command or sets its default

page 7-600

<10-3600>

Specifies the interval, in seconds, between successive DPD keep alive packets.The IKE keep alive
message interval is used to detect a dead peer on the remote end of the IPSec VPN tunnel. Specify the
time from 10 - 3600 seconds. The default is 30 seconds

Advertising