H3C S6550X-HI Series Command Reference Manual page 2270

Table of Contents

Advertisement

Views
IPsec transform set view
Predefined user roles
network-admin
Parameters
dh-group1
dh-group2
dh-group5
dh-group14
dh-group24
dh-group19
dh-group20
dh-group24
Usage guidelines
In terms of security and required calculation time, the following groups are in descending order:
384-bit ECP Diffie-Hellman group (dh-group20).
256-bit ECP Diffie-Hellman group (dh-group19).
2048-bit and 256-bit subgroup Diffie-Hellman group (dh-group24).
2048-bit Diffie-Hellman group (dh-group14).
1536-bit Diffie-Hellman group (dh-group5).
1024-bit Diffie-Hellman group (dh-group2).
768-bit Diffie-Hellman group (dh-group1).
If IKEv1 is used, the security level of the Diffie-Hellman group of the initiator must be higher than or
equal to that of the responder. This restriction does not apply to IKEv2.
The end without the PFS feature performs IKE negotiation according to the PFS requirements of the
peer end.
Examples
# Enable PFS using 2048-bit Diffie-Hellman group for IPsec transform set tran1.
<Sysname> system-view
[
]
Sysname
[
Sysname-ipsec-transform-set-tran1
policy enable
Use
policy enable
Use
undo policy enable
Syntax
policy enable
undo policy enable
Default
An IPsec policy entry or IPsec policy template entry is enabled.
: Uses 768-bit Diffie-Hellman group.
: Uses 1024-bit Diffie-Hellman group.
: Uses 1536-bit Diffie-Hellman group.
: Uses 2048-bit Diffie-Hellman group.
: Uses 2048-bit and 256-bit subgroup Diffie-Hellman group.
: Uses 256-bit ECP Diffie-Hellman group. This keyword is available only for IKEv2.
: Uses 384-bit ECP Diffie-Hellman group. This keyword is available only for IKEv2.
: Uses 2048-bit and 256-bit subgroup Diffie-Hellman group.
ipsec transform-set tran1
to enable an IPsec policy entry or IPsec policy template entry.
to disable an IPsec policy entry or IPsec policy template entry.
]
pfs dh-group14
45

Advertisement

Table of Contents
loading

Table of Contents