crypto-map
10-9
Usage Guidelines
WS5100(config-crypto-map)#set peer (name)
If no peer IP address is configured, the manual crypto map is not valid and not complete.
A peer IP address is required for manual crypto maps. To change the peer IP address, the
no set peer command must be issued first; then the new peer IP address can be configured.
WS5100(config-crypto-map)#set pfs
If left at the default setting, no perfect forward secrecy (PFS) is used during IPSec SA key
generation. If PFS is specified, the specified Diffie-Hellman Group exchange is used for the
initial (and all subsequent) key generation. This means no data linkage between prior keys
and future keys.
WS5100(config-crypto-map)#set security-association lifetime
(kilobytes|seconds)
Values can be entered in both kilobytes and seconds. Whichever limit is reached first, ends
the security association.
WS5100(config-crypto-map)#set session-key
(inbound|outbound)(ah|esp)
WS5100(config-crypto-map)#set session-key (inbound|outbound) ah
<hexkey data>
WS5100(config-crypto-map)#set session-key (inbound|outbound) esp
<SPI> cipher <hexdata key> authenticator <hexkey data>
inbound/outbound
(ah|esp)
Defines encryption keys for inbound/outbound traffic
•
ah –
Authentication header protocol
• <256-4294967295> –
Security Parameter
Index
(SPI) for the security association
•
esp –
Encapsulating security payload protocol
• <256-4294967295> – Derfines the security
parameter Index
• cipher – Specify encryption/decryption
key
•
authenticator <hex key data> –
Specify
an authentication key
transformset <name>
Use the set transform-set command to assign a transform-
set to a crypto map.
Summary of Contents for WS5100 Series
Page 1: ...M WS5100 Series Switch CLI Reference Guide ...
Page 14: ...WS5100 Series Switch CLI Reference Guide xviii ...
Page 28: ...WS5100 Series Switch CLI Reference Guide TOC 14 ...
Page 40: ...WS5100 Series Switch CLI Reference Guide 1 12 ...
Page 132: ...WS5100 Series Switch CLI Reference Guide 3 10 ...
Page 164: ...WS5100 Series Switch CLI Reference Guide 4 32 ...
Page 240: ...WS5100 Series Switch CLI Reference Guide 6 10 ...
Page 258: ...WS5100 Series Switch CLI Reference Guide 9 4 ...
Page 270: ...WS5100 Series Switch CLI Reference Guide 10 12 ...
Page 332: ...WS5100 Series Switch CLI Reference Guide 14 22 ...
Page 344: ...WS5100 Series Switch CLI Reference Guide 15 12 ...
Page 482: ...WS5100 Series Switch CLI Reference Guide 20 64 ...
Page 491: ......