clear ipsec sa

Clears IPsec security associations (SAs).
Syntax
clear ipsec sa [ fvrf vrf-name | ipv4 | peer ip-address ]
Parameters
fvrf vrf-name
Specifies the front-door VRF (FVRF) for the SAs.
ipv4
Specifies clearing IPv4 associations.
peer ip-address
Specifies clearing associations for the IPv4 address of a peer.
Modes

Privileged EXEC mode

Usage Guidelines

The clearing process deletes and re-establishes IPsec SAs. The SAs remain unchanged.

When optional parameters are not specified, this command clears all IPsec SAs on the device.

Note: Clearing all IPsec SAs is a costly operation. Therefore, the unqualified version of the command should be used with caution. Issuing multiple unqualified versions of the command within a short time frame is not recommended.
Examples

The following example clears all IPsec SAs on the device.

device# clear ipsec sa
History
Release version Command history
08.0.50 This command was introduced.