SonicWALL SSL-R User Manual page 116

Secure sockets layer ffloading solutions that allow servers to provide both secure and non-secure services at the same high speeds
Hide thumbs Also See for SSL-R:
Table of Contents

Advertisement

Security Policy Configuration Command Set
Use Security Policy Configuration commands to set up and manage security policies. Enter
Security Policy Configuration mode by using the configure command in Privileged mode,
the ssl command in the Configuration mode, and secpolicy command in SSL Configuration
mode.
Command:
Availability:
Description:
Command:
Availability:
Description:
Command:
Availability:
Description:
Page 116 SSL-IA/SSL-R User's Guide
[no] crypto < strong | weak | ARC4-MD5 | ARC4-SHA | DES-CBC3-MD5 |
DES-CBC3-SHA | DES-CBC-MD5 | DES-CBC-SHA | EXP-ARC2-MD5 |
EXP-ARC4-MD5 | EXP-ARC4-SHA | EXP-DES-CBC-SHA |
EXP1024-ARC2-CBC-MD5 | EXP1024-ARC4--MD5 |
EXP1024-ARC4-SHA | EXP1024-DES-CBC-SHA | NULL-MD5 | NULL-SHA >
Remote, Serial, Telnet
(This command must be entered on one line.) Creates a customized security policy
for the current SSL device. You may identify either individual ciphers or use the
keywords to specify cipher sets. The
ciphers. You must specify which algorithm(s) to remove following the
command.
You can load multiple cryptography schemes into a security policy. For example,
using the commands
crypto ARC4-MD5
into the current security policy. Additionally, you can alter the preset cryptography
schemes specified for the current security policy. If you enter
commands, the NULL-MD5 cryptography scheme is removed
crypto NULL-MD5
from the current security policy.
"ARC4" is compatible with RC4™ RSA Data Security. "ARC2" is
Note:
compatible with RC2™ RSA Data Security. The "strong" policy
includes ARC4-MD5, ARC4-SHA, DES-CBC3-MD5, DES-CBC3-SHA,
DES-CBC-MD5, and DES-CBC-SHA. The "weak" policy includes all
policies that are prefixed with "EXP-" or "NULL-". These policies are
considered to be export-level policies.
end
Remote, Serial, Telnet
Exits Security Policy Configuration mode, activates all changes, and returns to SSL
Configuration mode.
exit
Remote, Serial, Telnet
Exits Security Policy Configuration mode, activates all changes, and returns to SSL
Configuration mode.
flag is used to remove a cipher or set of
no
and
crypto ARC4-SHA
no crypto
loads both schemes
and
crypto weak
no

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ssl-ia

Table of Contents