Hardware
MSR5620/5660/5680
sm4-cbc: Uses the SM4 algorithm in CBC mode, which uses a 128-bit key. This keyword is available
only for IKEv1.
The following matrix shows the sm4-cbc keyword and hardware compatibility:
Hardware
MSR810/810-W/810-W-DB/810-LM/810-W-LM/810-10-Po
E/810-LM-HK/810-W-LM-HK/810-LMS/810-LUS
MSR2600-10-X1
MSR 2630
MSR3600-28/3600-51
MSR3600-28-SI/3600-51-SI
MSR3610-X1/3610-X1-DP/3610-X1-DC/3610-X1-DP-DC
MSR 3610/3620/3620-DP/3640/3660
MSR5620/5660/5680
Examples
# Use the 128-bit AES in CBC mode as the encryption algorithm for IKE proposal 1.
<Sysname> system-view
[Sysname] ike proposal 1
[Sysname-ike-proposal-1] encryption-algorithm aes-cbc-128
Related commands
display ike proposal
exchange-mode
Use exchange-mode to select an IKE negotiation mode for phase 1.
Use undo exchange-mode to restore the default.
Syntax
In non-FIPS mode:
exchange-mode { aggressive | main }
undo exchange-mode
In FIPS mode:
exchange-mode main
undo exchange-mode
Default
Main mode is used for phase 1.
Views
IKE profile view
Keyword compatibility
Yes
Keyword compatibility
Yes
No
No
No
No
Yes
Yes
Yes
587