05-04-2006 01:08 AM - edited 02-21-2020 12:52 AM
I been searching around the command to stop or terminate a tunnel instead of reload the unit. Anyone can advice me how to procees abt this?
Thank you very much.
05-04-2006 06:09 PM
Hi .. I hope it heps .. please rate if it does !!!
If the PIX Firewall is processing active IPSec traffic, we recommend that you only clear the portion of
the security association database that is affected by the changes to avoid causing active IPSec traffic to
temporarily fail.
The clear [crypto] ipsec sa command only clears IPSec security associations; to clear IKE security
associations, use the clear [crypto] isakmp sa command.
The following example clears (and reinitializes if appropriate) all IPSec security associations at the
PIX Firewall:
clear crypto ipsec sa
The following example clears (and reinitializes if appropriate) the inbound and outbound IPSec security
associations established along with the security association established for address 10.0.0.1 using the
AH protocol with the SPI of 256:
clear crypto ipsec sa entry 10.0.0.1 AH 256
05-04-2006 10:04 PM
Thanks you for the advice. Got it now. Appreciate that.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide