Security and authentication
9.3 IPsec VPN
Further notes
You display this setting and other information with the
You disable the use of the default list with the
9.3.7.11
ike-keyderivation
Description
With this command, you configure the required Diffie-Hellmann group (DH) from which a key
will be generated.
Requirement
● The default list is not used.
● You are in the IPSEC PHASE configuration mode.
cli(config-conn-phs1)#
Syntax
Call up the command with the following parameters:
ike-keyderivation {dhgroup <1|2|5|14|15|16|17|18>}
The parameters have the following meaning:
Parameter
auto
dhgroup
Result
The Diffie-Hellmann group (DH) is configured.
394
The command prompt is as follows:
Description
Automatic detection
Diffie-Hellmann group (DH)
show ipsec conn-phase1
command.
no default-ciphers
Range of values / note
-
Specify the required Diffie-Hellmann
group (DH).
•
1
•
2
•
5
•
14
•
15
•
16
•
17
•
18
SCALANCE S615 Command Line Interface
Configuration Manual, 06/2015, C79000-G8976-C406-02
command.