Exchange-Mode - HP 6125XLG Command Reference Manual

Blade switch security command reference
Table of Contents

Advertisement

Views
IKE proposal view
Predefined user roles
network-admin
Parameters
3des-cbc: Uses the 3DES algorithm in CBC mode as the encryption algorithm. The 3DES algorithm uses
a 168-bit key for encryption.
aes-cbc-128: Uses the AES algorithm in CBC mode as the encryption algorithm. The AES algorithm uses
a 128-bit key for encryption.
aes-cbc-192: Uses the AES algorithm in CBC mode as the encryption algorithm. The AES algorithm uses
a 192-bit key for encryption.
aes-cbc-256: Uses the AES algorithm in CBC mode as the encryption algorithm. The AES algorithm uses
a 256-bit key for encryption.
des-cbc: Uses the DES algorithm in CBC mode as the encryption algorithm. The DES algorithm uses a
56-bit key for encryption.
Usage guidelines
Different algorithms provide different levels of protection. Generally, an algorithm with a longer key is
stronger. A stronger algorithm provides more resistance to decryption but uses more resources. The
algorithm strength from low to high is des-cbc, 3des-cbc, aes-cbc-128, aes-cbc-192, and aes-cbc-256.
Examples
# Use the 192-bit AES in CBC mode as the encryption algorithm for IKE proposal 1.
<Sysname> system-view
[Sysname] ike proposal 1
[Sysname-ike-proposal-1] encryption-algorithm aes-cbc-192
Related commands
display ike proposal

exchange-mode

Use exchange-mode to select an IKE negotiation mode for phase 1.
Use undo exchange-mode to restore the default.
Syntax
In non-FIPS mode:
exchange-mode { aggressive | main }
undo exchange-mode
In FIPS mode:
exchange-mode main
undo exchange-mode
Default
Main mode is used for phase 1.
285

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents