Brocade Communications Systems 8 Command Reference Manual page 470

Fabric os command reference manual supporting fabric
Hide thumbs Also See for 8:
Table of Contents

Advertisement

2
ipSecConfig
438
policy ike
Creates or modifies an IKE policy configuration. No subtype is required with
this command. The command defines the following IKE policy parameters:
IKE version, IP address of the remote entity, IP address of the local entity,
encryption algorithm, hash algorithm, PRF algorithm, DH group,
authentication method, path and filename of the preshared key. The syntax is
as follows: ipsecConfig --add | --modify ike arguments.
arguments
Valid arguments for policy ike include:
-tag name
Specifies a name for the IKE policy. This is a user-generated name. The
name must be between 1 and 32 characters in length, and may include
alphanumeric characters, dashes (-), and underscores (_). This operand
is required.
remote IP_address[/prefixlength]
Specifies the peer IPv4 or IPv6 address and prefix.
-id identifier
Specifies the local identifier. The switch is identified by its IPv4 or IPv6
address.
-remoteid identifier
Specifies the peer identifier. The remote peer is identified by its IPv4 or
IPv6 address.
-enc algorithm
Specifies the encryption algorithm. Valid encryption algorithms include
the following:
-hash algorithm Specifies the hash algorithm. Valid hash algorithms include the following:
-prf algorithm
Specifies the PFR algorithm. Valid PRF algorithms include the following:
-auth psk|dss|rsasig
Specifies the authentication method as one of the following:
psk
dss
rsasig
-dh number
Specifies the DH group number as one of the following:
1
2
14 Specifies DH group modp2048.
3des_cbc - 3DES algorithm
blowfish_cbc - Blowfish algorithm
aes128_cbc - AES 128-bit algorithm
aes256_cbc - AES 256-bit algorithm
null_enc - Null encryption algorithm (cleartext)
hmac_md5 - MD5 algorithm
hmac_sha1 - SH1 algorithm
hmac_md5 - MD5 algorithm
hmac_sha1 - SH1 algorithm
Authenticate using preshared keys.
Authenticate using digital signature standard.
Authenticate using an RSA signature.
Specifies DH group modp768.
Specifies DH group modp1024.
Fabric OS Command Reference
53-1001764-02

Advertisement

Table of Contents
loading

Table of Contents