4 – Network Configuration
Managing IP Security
59263-02 A
4-17
A
Modifying a User-Defined Association
To modify an existing user-defined association, enter the
Ipsec Association
Edit
command in an Admin session and an Ipsec Edit session as shown in the
following example. An asterisk (*) indicates a required entry.
SANbox (admin-ipsec) #> ipsec association edit h2h-sh-sa
A list of attributes with formatting and current values will follow.
Enter a new value or simply press the ENTER key to accept the current value.
To remove a value for an optional attribute, use ’n’.
If you wish to terminate this process before reaching the end of the list
press 'q' or 'Q' and the ENTER key to do so.
Current Values:
Description Host-to-host: switch->host
.
.
EncryptionKey 123456789012345678901234
New Value (press ENTER to not specify value, 'q' to quit, 'n' for none):
Description (string value, 0-127 bytes) :
*SourceAddress (IPv4, IPv6 or hostname) :
*DestinationAddress (IPv4, IPv6 or hostname) :
*Protocol (1=esp, 2=esp-old, 3=ah, 4=ah-old) : ah
*SPI (decimal value, 256-4294967295) :
Authentication (select an authentication algorithm)
1=hmac-md5 (16 byte key)
2=hmac-sha1 (20 byte key)
3=hmac-sha256 (32 byte key)
4=aes-xcbc-mac (16 byte key)
authentication algorithm choice :
*AuthenticationKey (quotes string or raw hex bytes) :
*Encryption (select an encryption algorithm)
1=des-cbc (8 byte key)
2=3des-cbc (24 byte key)
3=null (0 byte key)
4=blowfish-cbc (5-56 byte key)
5=aes-cbc (16/24/32 byte key)
6=twofish-cbc (32 byte key)
encryption algorithm choice :
*EncryptionKey (quoted string or raw hex bytes) :
The security association has been edited.
This configuration must be saved with the 'ipsec save' command
before it can take effect, or to discard this configuration
use the 'ipsec cancel' command.
SANbox (admin-ipsec) #> ipsec save
The IPsec configuration will be saved and activated.
Please confirm (y/n): [n] y
Summary of Contents for SANbox 5800V Series
Page 28: ...2 Command Line Interface Usage Downloading and Uploading Files 2 10 59263 02 A S Notes...
Page 52: ...4 Network Configuration Managing IP Security 4 20 59263 02 A S Notes...
Page 86: ...5 Switch Configuration Managing Idle Session Timers 5 34 59263 02 A S Notes...
Page 104: ...6 Port Configuration Displaying Extended Credit Status 6 18 59263 02 A S Notes...
Page 154: ...11 Event Log Configuration Creating and Downloading a Log File 11 8 59263 02 A S Notes...
Page 172: ...12 Call Home Configuration Resetting the Call Home Database 12 18 59263 02 A S Notes...
Page 406: ...14 Command Reference Command Listing 14 226 59263 02 A S...
Page 421: ......