WS5100 Series Switch CLI Reference Guide
10-8
pfs
Use the
set pfs
command to choose the type of perfect
forward secrecy (if any) required during IPSec negotiation of
SAs for this crypto map. Use the no form of this command
to require no PFS
•
group 1 –
IPSec is required to use the Diffie-Hellman
Group 1 (768-bit modulus) exchange during IPSec SA key
generation
•
group 2 –
IPSec is required to use the Diffie-Hellman
Group 2 (1024-bit modulus) exchange during IPSec SA
key generation
•
group 5 –
IPSec is required to use Diffie-Hellman Group 5
remote-type
Sets the remote VPN client type.
• ipsec-l2tp – Specify the remote VPN client as using
IPSEC/L2TP
• xauth – Specify the remote VPN client as using XAUTH
with mode config
security-association
Defines the lifetime (in kilobytes and/or seconds) of the
IPSec SAs created by this crypto map
•
level(perhost) –
Specify a security association
granularity level for identities
•
lifetime(kilobyte|seconds) –
Security an association
lifetime
session-key
Use the set session-key command to define the encryption
and authentication keys for this crypto map
•
inbound –
Defines encryption keys for inbound traffic
•
outbound –
Defines encryption keys for outbound traffic
Summary of Contents for WS5100 Series
Page 1: ...M WS5100 Series Switch CLI Reference Guide ...
Page 14: ...WS5100 Series Switch CLI Reference Guide xviii ...
Page 28: ...WS5100 Series Switch CLI Reference Guide TOC 14 ...
Page 40: ...WS5100 Series Switch CLI Reference Guide 1 12 ...
Page 132: ...WS5100 Series Switch CLI Reference Guide 3 10 ...
Page 164: ...WS5100 Series Switch CLI Reference Guide 4 32 ...
Page 240: ...WS5100 Series Switch CLI Reference Guide 6 10 ...
Page 258: ...WS5100 Series Switch CLI Reference Guide 9 4 ...
Page 270: ...WS5100 Series Switch CLI Reference Guide 10 12 ...
Page 332: ...WS5100 Series Switch CLI Reference Guide 14 22 ...
Page 344: ...WS5100 Series Switch CLI Reference Guide 15 12 ...
Page 482: ...WS5100 Series Switch CLI Reference Guide 20 64 ...
Page 491: ......