424
CN4093 Application Guide for N/OS 8.4
Enabling IKEv2 Preshared Key Authentication
To
set
up
IKEv2
preshared
key
authentication:
1.
Enter
the
local
preshared
key.
2.
If
asymmetric
authentication
is
supported,
enter
the
remote
key:
where
the
following
parameters
are
used:
preshared
key
A
string
of
1
‐
256
characters
IPv6
host
An
IPv6
‐
format
host,
such
as
“3000::1”
3.
Set
up
the
IKEv2
identification
type
by
entering
one
of
the
following
commands:
To
disable
IKEv2
RSA
‐
signature
authentication
method
and
enable
preshared
key
authentication,
enter:
Setting Up a Key Policy
When
configuring
IPsec,
you
must
define
a
key
policy.
This
key
policy
can
be
either
manual
or
dynamic.
Either
way,
configuring
a
policy
involves
the
following
steps:
Create
a
transform
set—This
defines
which
encryption
and
authentication
algo
‐
rithms
are
used.
Create
a
traffic
selector—This
describes
the
packets
to
which
the
policy
applies.
Establish
an
IPsec
policy.
Apply
the
policy.
1.
To
define
which
encryption
and
authentication
algorithms
are
used,
create
a
transform
set:
where
the
following
parameters
are
used:
transform
ID
A
number
from
1
‐
10
encryption
method
One
of
the
following:
esp-des
|
esp-3des
|
esp-aes-cbc
|
esp-null
integrity
algorithm
One
of
the
following:
esp-sha1
|
esp-md5
|
none
AH
authentication
algorithm
One
of
the
following:
ah-sha1
|
ah-md5
|
none
CN 4093(config)#
ikev2 preshare-key local
<preshared
key,
a
string
of
1
‐
256
chars>
CN 4093(config)#
ikev2 preshare-key remote
<
preshared
key>
<IPv6
host
>
CN 4093(config)#
ikev2 identity local address
(
use
an
IPv6
address)
CN 4093(config)#
ikev2 identity local email
<
address
>
CN 4093(config)#
ikev2 identity local fqdn
<
domain
name
>
CN 4093(config)#
no access https
CN 4093(config)#
ipsec transform-set
<transform
ID>
<encryption
method>
<integrity
algorithm>
<AH
authentication
algorithm>
Summary of Contents for Flex System Fabric CN4093
Page 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Page 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Page 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Page 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Page 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Page 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Page 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Page 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Page 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Page 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Page 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Page 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Page 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Page 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Page 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Page 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Page 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Page 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Page 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Page 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Page 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Page 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Page 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Page 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Page 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Page 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Page 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Page 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Page 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Page 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Page 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Page 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Page 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Page 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Page 633: ......
Page 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...