T
C
O
ONFIGURE
Command (in IKE Policy CM)
authentication {pre-shared|rsa-sig}
E
XAMPLE
ALU(config-crypto-ike-policy-P1)# authentication pre-shared
Note:
If the Authentication type is not explicitly configured, default pre-shared is used.
T
C
T
O
ONFIGURE
RANSFORM
A transform set represents a certain combination of security protocols and
algorithms. During the IPsec security association negotiation, the peers agree to
use a particular transform set for protecting a particular data flow.
Note:
You can specify a maximum of 4 values in a transform set.
crypto ipsec transform-set <name>
{<algo>[<algo>][<algo>] [<algo>]}
[force]
Note:
The "force" keyword is used to modify or edit the transform-set in use.
Options for proposal under transform-set:
•
esp-md5-3des
•
esp-md5-aes128 encapsulation with MD5 and 128 bit AES encryption
•
esp-md5-aes192 encapsulation with MD5 and 192 bit AES encryption
•
esp-md5-aes256 encapsulation with MD5 and 256 bit AES encryption
•
esp-md5-des
•
esp-sha1-3des
•
esp-sha1-aes128 encapsulation with SHA1 and 128 bit AES encryption
•
esp-sha1-aes192 encapsulation with SHA1 and 192 bit AES encryption
•
esp-sha1-aes256 encapsulation with SHA1 and 256 bit AES encryption
•
esp-sha1-des
CLI Configuration Guide
Beta
A
T
UTHENTICATION
YPE
-
IP
SET IN
SEC
Command (in CM)
encapsulation with MD5 and 3DES encryption
encapsulation with MD5 and 56 bit DES encryption
encapsulation with SHA1 and 3DES encryption
encapsulation with SHA1 and 56 bit DES encryption
Alcatel-Lucent
Except on the first page, right running head:
Heading1 or Heading1NewPage text (automatic)
Description
This command configures the
authentication type to be used
during IKE negotiation.
Description
This command creates a
transform-set.
IPsec VPN Configuration
767
Beta