Set (Ipsec Crypto Map Configuration Submode) - Cisco AJ732A - MDS 9134 Fabric Switch Command Reference Manual

Cisco mds 9000 family command reference guide - release 4.x (ol-18089-01, february 2009)
Hide thumbs Also See for AJ732A - Cisco MDS 9134 Fabric Switch:
Table of Contents

Advertisement

Chapter 21
S Commands
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m

set (IPsec crypto map configuration submode)

To configure attributes for IPsec crypto map entries, use the set command in IPsec crytpo map
configuration submode. To revert to the default values, use the no form of the command.
Syntax Description
peer
ip-address
auto-peer
pfs
group1
group14
group2
group5
security-association
lifetime
gigabytes number
kilobytes number
megabytes number
seconds number
transform-set
set-name
set-name-list
Defaults
None.
PFS is disabled by default. When it is enabled without a group parameter, the default is group1.
The security association lifetime defaults to global setting configured by the crypto global domain
ipsec security-association lifetime command.
Command Modes
IPsec crypto map configuration submode.
OL-18089-01, Cisco MDS NX-OS Release 4.x
set {peer {ip-address | auto-peer} | pfs [group1 | group14 | group2 | group5] |
security-association lifetime {gigabytes number | kilobytes number | megabytes number |
seconds number} | transform-set {set-name | set-name-list}}
no set {peer {ip-address | auto-peer} | pfs | security-association lifetime {gigabytes | kilobytes |
megabytes | seconds} | transform-set}
Specifies an allowed encryption/decryption peer.
Specifies a static IP address for the destination peer.
Specifies automatic assignment of the address for the destination peer.
Specifies the perfect forwarding secrecy.
(Optional) Specifies PFS DH Group1 (768-bit MODP).
(Optional) Specifies PFS DH Group14 (2048-bit MODP).
(Optional) Specifies PFS DH Group2 (1024-bit MODP).
(Optional) Specifies PFS DH Group5 (1536-bit MODP).
Specifies the security association lifetime in traffic volume or time in
seconds.
Specifies a volume-based key duration in gigabytes. The range is 1 to 4095.
Specifies a volume-based key duration in kilobytes. The range is 2560 to
2147483647.
Specifies a volume-based key duration in megabytes. The range is 3 to
4193280.
Specifies a time-based key duration in seconds. The range is 120 to 86400.
Configures the transform set name or set name list.
Specifies a transform set name. Maximum length is 63 characters.
Specifies a comma-separated transform set name list. Maximum length of
each name is 63 characters. You can specified a maximum of six lists.
set (IPsec crypto map configuration submode)
Cisco MDS 9000 Family Command Reference
21-27

Advertisement

Table of Contents
loading

Table of Contents