25-87
Cisco Prime Network 4.0 User Guide
OL-29343-01
Chapter 25 Monitoring Mobile Technologies LTE Networks
Viewing the EAP Profile Details
To view the EAP Profile details:
Rekey Indicates whether IPSec Child Security Association rekeying must be
enabled, after approximately 90% of the child SA lifetime has expired.
Rekey Keepalive Indicates whether rekeying must be allowed if data is not received on the
security association since the last rekey.
TSI Start Address The IKEv2 Initiator Traffic Selector payload start address configured for the
crypto template.
TSI End Address The IKEv2 Initiator Traffic Selector payload end address configured for the
crypto template.
TSR Start Address The IKEv2 Responder Traffic Selector payload start address.
TSR End Address The IKEv2 Responder Traffic Selector payload end address.
Crypto Template IKESAs
IKESA Instance The IKESA instance configured for the crypto template.
Allow Empty IKESA Indicates whether empty IKESA is allowed. By default, empty IKESA is not
allowed.
Certificate Sign The certificate sign to be used. This field defaults to pkcs1.5.
Ignore Notify Protocol
ID Indicates whether the IKEv2 Exchange Notify Payload Protocol-ID values
must be ignored for strict RFCA 4306 compliance.
Ignore Rekeying
Requests Indicates whether IKESA rekeying requests must be ignored.
Keepalive User Activity Indicates whether the user inactivity timer must be reset when keepalive
messages are received from the peer.
Max Retransmission The maximum number of retransmissions of an IKEv2 IKE excha nge request
that is allowed if a response is not received.
Policy Congestion
Rejection Notify Status Indicates whether an error notification message must be sent in response to
an IKE_SA INIT exchange, when IKESA sessions cannot be established
anymore.
Policy Error Notification Indicates whether an error notification message must be sent for invalid
IKEv2 exchange message ID and syntax.
Rekey Indicates whether IKESA rekeying must occur before the co nfigured
lifetime expires (which is approximately at 90% of the lifetime interval). By
default, rekeying is not allowed.
Retransmission Timeout The time period (in milliseconds) that must elapse before a retransmission of
an IKEv2 IKE exchange request is sent when a corresponding response is not
received.
Setup Timer The number of seconds before a IKEv2 security association, which is not
fully established, is terminated.
Table 25-52 Crypto Template Details (continued)
Field Description