Clearing Security Associations
Certain configuration changes take effect only during the negotiation of subsequent SAs. If you want the new settings to take effect immediately, clear the existing SAs to reestablish them with the changed configuration. If the security appliance is actively processing IPSec traffic, clear only the portion of the SA database that the configuration changes affect. Reserve clearing the full SA database for large-scale changes, or when the security appliance is processing a small amount of IPSec traffic.
Table 27-6 lists commands you can enter to clear and reinitialize IPSec SAs.
|
Command |
Purpose |
|
clear configure crypto |
Removes an entire crypto configuration, including IPSec, crypto maps, dynamic crypto maps, and ISAKMP. |
|
clear configure crypto ca trustpoint |
Removes all trustpoints. |
|
clear configure crypto dynamic-map |
Removes all dynamic crypto maps. Includes keywords that let you remove specific dynamic crypto maps. |
|
clear configure crypto map |
Removes all crypto maps. Includes keywords that let you remove specific crypto maps. |
|
clear configure crypto isakmp |
Removes the entire ISAKMP configuration. |
|
Removes all ISAKMP policies or a specific policy. |
|
|
Removes the entire ISAKMP SA database. |
Continue reading here: Configuring L2TP over IPSec Connections
Was this article helpful?