set vpn site-to-site period-after-crl-not-valid

Description

Configures the time (in seconds), after which a revoked certificate of a remote VPN site remains valid.

This is to allow a wider window for CRL validity in case of mismatch in clock on the VPN sites.

Syntax

set vpn site-to-site advanced-settings period-after-crl-not-valid <threshold>

Parameters

Parameter

Description

<threshold>

An integer between 0 and 4,294,967,295.

The default is 1800.

Example

set vpn site-to-site advanced-settings period-after-crl-not-valid 2000