replay-protection

Used with extended sequence numbering in IPsec to prevent replay attacks by assigning each encrypted packet an increasing sequence number that is tracked at the IPsec endpoint.
Syntax
replay-protection
no replay-protection
Command Default

Anti-replay protection is disabled by default.

Modes

IPsec profile configuration sub-mode

Usage Guidelines

The replay-protection command must be used in conjunction with extended sequence numbering (ESN), which is configured with the esn-enable command in the IPsec proposal.

The no form of the command disables anti-replay protection.

Examples

The following example configures IPsec anti-replay protection as part of the IPsec profile ipsecprof1.

device# configure terminal
device(config)# ipsec profile ipsecprof1
device(config-ipsec-profile-ipsecprof1)# replay-protection
History
Release version Command history
08.0.70 This command was introduced.