H3C S6550X-HI Series Command Reference Manual page 2309

Table of Contents

Advertisement

aes-cbc-128
for encryption.
aes-cbc-192
for encryption.
aes-cbc-256
for encryption.
: Specifies the DES algorithm in CBC mode. The DES algorithm uses a 56-bit key for
des-cbc
encryption.
Examples
# Use the 128-bit AES algorithm in CBC mode as the encryption algorithm for IKE proposal 1.
<Sysname> system-view
[Sysname] ike proposal 1
[Sysname-ike-proposal-1] encryption-algorithm aes-cbc-128
Related commands
display ike proposal
exchange-mode
Use
exchange-mode
Use
undo exchange-mode
Syntax
exchange-mode { aggressive | main }
undo exchange-mode
Default
Main mode is used for phase 1.
Views
IKE profile view
Predefined user roles
network-admin
Parameters
aggressive
main
: Specifies the main mode.
Usage guidelines
As a best practice, specify the
met:
The local end, for example, a dialup user, obtains an IP address automatically.
Preshared key authentication is used.
Examples
# Specify that IKE negotiation operates in main mode.
<Sysname> system-view
[Sysname] ike profile 1
: Specifies the AES algorithm in CBC mode. The AES algorithm uses a 128-bit key
: Specifies the AES algorithm in CBC mode. The AES algorithm uses a 192-bit key
: Specifies the AES algorithm in CBC mode. The AES algorithm uses a 256-bit key
to select an IKE negotiation mode for phase 1.
to restore the default.
: Specifies the aggressive mode.
aggressive
mode at the local end if the following conditions are
15

Advertisement

Table of Contents
loading

Table of Contents