Clearing Security Associations

Certain configuration changes take effect only during the negotiation of subsequent SAs. If you want the new settings to take effect immediately, clear the existing SAs to reestablish them with the changed configuration. If the security appliance is actively processing IPSec traffic, clear only the portion of the SA database that the configuration changes affect. Reserve clearing the full SA database for large-scale changes, or when the security appliance is processing a small amount of IPSec traffic.

Table 27-6 lists commands you can enter to clear and reinitialize IPSec SAs.

Table 27-6 Commands to Clear and Reinitialize IPSec SAs

Command

Purpose

clear configure crypto

Removes an entire crypto configuration, including IPSec, crypto maps, dynamic crypto maps, and ISAKMP.

clear configure crypto ca trustpoint

Removes all trustpoints.

clear configure crypto dynamic-map

Removes all dynamic crypto maps. Includes keywords that let you remove specific dynamic crypto maps.

clear configure crypto map

Removes all crypto maps. Includes keywords that let you remove specific crypto maps.

clear configure crypto isakmp

Removes the entire ISAKMP configuration.

clear configure crypto isakmp policy

Removes all ISAKMP policies or a specific policy.

clear crypto isakmp sa

Removes the entire ISAKMP SA database.

Continue reading here: Configuring L2TP over IPSec Connections

Was this article helpful?

0 0