Policy - Brocade Communications Systems A7533A - Brocade 4Gb SAN Switch Base Command Reference Manual

Brocade fabric os command reference manual - supporting fabric os v5.3.0 (53-1000436-01, june 2007)
Hide thumbs Also See for A7533A - Brocade 4Gb SAN Switch Base:
Table of Contents

Advertisement

policy

Displays or modifies the encryption and authentication algorithms for security policies.
Synopsis
policy option type number [--enc method] [--auth algorithm] [--pfs value] [--dh group] [--seclife
seconds]
Description
Use this command to display or modify the encryption and authentication algorithms for security
policies. You can configure a maximum of 32 Internet key exchange (IKE) and 32 Internet protocol
security (IPSec) policies.
Each FCIP tunnel is configured separately and might have the same or different IKE and IPSec
policies.
Policies cannot be altered. To change the parameters associated with a current IKE or IPSec
ike, that policy must be deleted and re-created with new parameters.
A policy cannot be deleted while an active FCIP tunnel is using it.
Operands
option
type
number
Optional
-enc method
Operands
-auth algorithm
-pfs value
-dh group
Fabric OS Command Reference Manual
53-1000436-01
Specifies the action to take. Actions include:
--create
Creates the policy.
--delete
Deletes the policy.
--show
Displays the policy.
Specifies the policy type. Types include:
--ike
Internet key exchange.
--ipsec Internet protocol security.
Specifies the numeric ID of the policy. Valid values are 1 to 32, and ALL with
the --show option.
Specifies the encryption algorithm. The default is AES-128. Methods include:
3DES
Triple data encryption standard, 192-bit key.
AES-128
Advanced encryption standard, 128-bit key.
AES-256
Advanced encryption standard, 256-bit key.
Specifies the authentication algorithm. The default is SHA-1. Algorithms
include:
SHA-1 Secure hash algorithm.
MD5
Message digest 5
AES-XCBCAdvanced encryption standard. Valid only wiht IPSec.
Specifies the perfect forward secrecy. This operand is valid only with IKE
policies. Values are on (default) or off.
Specifies the Diffie-Hellman group used in PFS negotiation. This operand is
valid only with IKE policies. The default is 1. Values include:
1
Fastest as it uses 768 bit values, but least secure.
14
Slowest as it uses 2048 bit values, but most secure.
2
policy
441

Advertisement

Table of Contents
loading

Table of Contents