Cisco – How to force a Cisco 2811 to rekey

ciscoipsec

We are having a IPsec/GRE VPN tunnel issue at work. Our vendor told me he "forced a rekey" and everything started working again. He alluded to a command to this, but didn't tell me the exact one. Does anyone know how to force a IPSec VPN to rekey?

Best Answer

I can't recall ever seeing anything to force a rekey; he may have just cleared the security association and let it build a new one. clear crypto sa peer x.x.x.x will keep the phase 1 and rebuild phase 2, clear crypto isakmp id with the id from show crypto isakmp sa will reset the whole tunnel.