Brocade Communications Systems NetIron MLXe Series Hardware Installation Manual page 52

Table of Contents

Advertisement

Router modules
Configuring the IPsec Proposal
Configure the IPsec proposal to specify the IPsec encryption parameters. The IPsec proposal contains the ESP and AH method to be
used. This will be linked to an IPsec policy.
The default proposal ipsec-default-proposal is defined at IPsec initialization time with the following parameters:
Authentication and encryption: esp- aes-gcm-256
transform esp
encapsulation-mode tunnel
IKEv2 Option
ipsec proposal <name>
encapsulation-mode {transport |
tunnel}
encryption-algorithm {aes-
gcm-256}
transform {esp}
ESN-enable
Configuring the IPsec Profile
The IPsec profile configuration defines the IPsec parameters to be used for encryption between IPsec routers.
For the IPSEC profile to be active and used for creating child-SA, the profile should be attached with a VTI interface. The profile should
have an IPsec proposal defined; otherwise, it will use the default IPsec proposal.
NOTE
There is no support for manual IPsec key entry.
If there is no IKE peer (source, destination, and VRF of VTI), then attaching the IPsec profile to VTI should initiate a new IKE session (if
the IKE profile is not configured as passive).
If there is already an IKE peer for the given source, destination, IKE profile and outgoing VRF, then a new child-SA should be created.
IKEv2 Option
ipsec Profile <name>
Description <string>
Ike-profile <ike-profile-name>
Lifetime [minutes]
52
Description
Defines an IPsec Security Proposal Name and enters IPsec proposal configuration mode.
The packet encapsulation mode is configured. By default, the security protocol uses the tunnel mode to
encapsulate IP packets.
NOTE
In the first release, only tunnel mode will be
supported.
Configure the encryption algorithm to be supported.
NOTE
For the first release gcm-256 is
supported.
Configure transform to be used.
For release 5.8.00 esp will be supported.
Enable Extended Sequence Number in this transform. By default it is disabled. Use this command to enable it.
NOTE
The setting for this command must match the setting for replay-protection (for the IPsec
profile).
Description
Defines the IPsec parameters to be used between two IPsec routers, and enter IPsec configuration mode.
(Optional) Description text for this IPsec profile.
IKE profile attached with this IPsec profile.
(Optional) Lifetime of the IPsec SA in minutes. By default it is 8 hours, 480 minutes. The new security association
will be started 5 minutes before the old one is about to expire.
Brocade NetIron MLXe Series Hardware Installation Guide
53-1004203-04

Advertisement

Table of Contents
loading

Table of Contents