esn-enable (IPsec)

Used with replay-protection in IPsec to enable 64-bit sequence numbering for encrypted packets for tracking and verification by the receiving IPsec endpoint.
Syntax
esn-enable
no esn-enable
Command Default

Extended sequence numbering (ESN) is disabled by default.

Modes

IPsec proposal configuration sub-mode

Usage Guidelines

Configure ESN as part of the IPsec proposal.

ESN must be used in conjunction with replay-protection (configured in the IPsec profile).

Clear IPsec security associations (SAs) for the command to take effect.

The no form of the command disables ESN.

Examples

The following example enables ESN in the IPsec proposal ipsecprop1.

device# configure terminal
device(config)# ipsec proposal ipsecprop1
device(config-ipsec-proposal-ipsecprop1)# esn-enable
History
Release version Command history
08.0.70 This command was introduced.