Default-Ciphers - Siemens SCALANCE S615 Configuration Manual

Simatic net industrial ethernet security command line interface
Hide thumbs Also See for SCALANCE S615:
Table of Contents

Advertisement

Security and authentication
9.3 IPsec VPN
Further notes
You display this setting and other information with the
You enable the setting with the
9.3.8.3

default-ciphers

Description
With this command, you specify that a preset list (default list) is transferred to the VPN
connection partner during connection establishment. The list contains a combination of the
three algorithms (Encryption, Authentication, Key Derivation).
To establish a VPN connection, the VPN connection partner must support at least one of
these combinations. The combinations depend on the phase und the key exchange method
IKE).
Combination
Encryption
Authentica-
tion
AES128
SHA1
AES256
SHA512
AES128 CCM 16
SHA256
AES256 CCM 16
SHA512
AES128
SHA1
AES256
SHA512
AES128 CCM 16
SHA256
AES256 CCM 16
SHA512
x: is supported
-: is not supported
none: For phase 2, no separate keys are exchanged. This means that Perfect Forward Secrecy PFS) is disabled.
Requirement
You are in the IPSEC PHASE configuration mode.
The command prompt is as follows:
cli(config-conn-phsX)#
X: 1 (Phase 1)
2 (Phase 2)
Syntax
Call the command without parameter assignment:
default-ciphers
398
auto-fwrules
Key Derivation
IKEv1
DH Group 14
DH Group 16
DH Group 14
DH Group 16
none
none
none
none
show ipsec conn-phase2
command.
Phase 1
IKEv2
x
x
x
x
-
x
-
x
-
-
-
-
-
-
-
-
SCALANCE S615 Command Line Interface
Configuration Manual, 06/2015, C79000-G8976-C406-02
command.
Phase 2
IKEv1
IKEv2
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents