Configuring IKEv2 ······················································································· 306
Overview ························································································································································ 306
IKEv2 negotiation process ····················································································································· 306
New features in IKEv2 ···························································································································· 307
Protocols and standards ························································································································ 307
IKEv2 configuration task list ··························································································································· 307
Configuring an IKEv2 profile ·························································································································· 308
Configuring an IKEv2 policy ··························································································································· 311
Configuring an IKEv2 proposal ······················································································································ 311
Configuring an IKEv2 keychain ······················································································································ 313
IKEv2 configuration examples ······················································································································· 315
Troubleshooting IKEv2 ··································································································································· 323
Configuring SSH ························································································· 325
Overview ························································································································································ 325
How SSH works ····································································································································· 325
SSH authentication methods ·················································································································· 326
SSH support for Suite B ························································································································· 327
Protocols and standards ························································································································ 328
FIPS compliance ············································································································································ 328
Generating local key pairs ······················································································································ 328
Enabling the Stelnet server ···················································································································· 329
Enabling the SFTP server ······················································································································ 329
Enabling the SCP server ························································································································ 330
Configuring an SSH user ······················································································································· 332
Working with SFTP directories ··············································································································· 341
Working with SFTP files ························································································································· 341
Displaying help information ···················································································································· 341
Specifying algorithms for SSH2 ····················································································································· 344
vii