Default-Ciphers - Siemens SCALANCE S615 Configuration Manual

Simatic net industrial ethernet security command line interface
Hide thumbs Also See for SCALANCE S615:
Table of Contents

Advertisement

9.3.7.3

default-ciphers

Description
With this command, you specify that a preset list (default list) is transferred to the VPN
connection partner during connection establishment. The list contains a combination of the
three algorithms (Encryption, Authentication, Key Derivation).
To establish a VPN connection, the VPN connection partner must support at least one of
these combinations. The combinations depend on the phase und the key exchange method
IKE).
Combination
Encryption
Authentica-
tion
AES128
SHA1
AES256
SHA512
AES128 CCM 16
SHA256
AES256 CCM 16
SHA512
AES128
SHA1
AES256
SHA512
AES128 CCM 16
SHA256
AES256 CCM 16
SHA512
x: is supported
-: is not supported
none: For phase 2, no separate keys are exchanged. This means that Perfect Forward Secrecy PFS) is disabled.
Requirement
You are in the IPSEC PHASE configuration mode.
The command prompt is as follows:
cli(config-conn-phsX)#
X: 1 (Phase 1)
2 (Phase 2)
Syntax
Call the command without parameter assignment:
default-ciphers
Result
The default list is used.
SCALANCE S615 Command Line Interface
Configuration Manual, 06/2015, C79000-G8976-C406-02
Key Derivation
IKEv1
DH Group 14
DH Group 16
DH Group 14
DH Group 16
none
none
none
none
Phase 1
IKEv2
x
x
x
x
-
x
-
x
-
-
-
-
-
-
-
-
Security and authentication
9.3 IPsec VPN
Phase 2
IKEv1
IKEv2
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
387

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents