Motorola Netopia® Router Connection Profile Commands 3-33

Note: It is a run-time checked error if both of the IKE Phase 2 SA lifetime values for a particular protocol are set to zero or none.

ICMP Dead Peer Detection Commands

Beginning with the version 8.2 firmware release, the Command Line Interface supports the following new and modified Connection Profile configuration commands:

IKE/IPSec Dead Peer Detection Connection Profile Commands

cp { name index } ipsec dead-peer-detection enable { yes no } no cp { name index } ipsec dead-peer-detection

show cp { name index } ipsec dead-peer-detection enable

cp { name index } ipsec dead-peer-detection ping-address remote net IPv4 address show cp { name index } ipsec dead-peer-detection ping-address

cp { name index } ipsec dead-peer-detection ping-retry 1...65535 show cp { name index } ipsec dead-peer-detection ping-retry

cp { name index } ipsec dead-peer-detection ping-reply-timeout 1...65535 show cp { name index } ipsec dead-peer-detection ping-reply-timeout

cp { name index } ipsec dead-peer-detection enable { yes no } no cp { name index } ipsec dead-peer-detection

show cp { name index } ipsec dead-peer-detection enable

These commands allow you to enable, disable, or show the status of the ICMP Dead Peer Detection feature. The no cp… command is equivalent to specifying the no option.

cp { name index } ipsec dead-peer-detection ping-address remote net IPv4 address show cp { name index } ipsec dead-peer-detection ping-address

These commands allow you to specify or show the IP destination host address that will be used to verify if the peer is dead or not. The IP address must belong to a tunnel’s remote network. A tunnel’s remote network can be configured as a subnet, an address range, or an individual host. The subnet remote network case also disallows the host part of the address to be all ones or all zeroes. For example, the addresses 163.176.0.0 or 163.176.255.255 are not permitted in a class B network.

cp { name index } ipsec dead-peer-detection ping-retry 1...65535 show cp { name index } ipsec dead-peer-detection ping-retry

These commands allow you to specify or show the retry interval between successive pings (in seconds). Default is 5 seconds.

Page 177
Image 177
Netopia CLI 874 manual Icmp Dead Peer Detection Commands