DLS/WBM can be used to deactivate SPE for all HFA/ SIP subscribers.
This causes all subscribers to log off and then log on via TCP.
The gateways themselves remain in secure mode, but no encryption
methods are used as long as all clients are connected via TCP.
CIPHER clients will not work correctly unless they are modified in
AMO SDAT to SECURE.
Activating SPE
As for deactivation, again using DLS/WBM.
Subscribers will log off and log on when SPE is activated or deactivated.
IMPORTANT:
The gateways must already be in secure mode when
the clients log on over TLS.