362
Predefined user roles
network-admin
mdc-admin
Parameters
start-time
: Specifies the start time in the HH:MM:SS format. The value range for this argument is
0:0:0 to 23:59:59.
start-date
: Specifies the start date in the MM/DD/YYYY or YYYY/MM/DD format. The value range for
YYYY is 2000 to 2035.
duration
duration-value
: Specifies the lifetime of the key, in the range of 1 to 2147483646 seconds.
duration
infinite
: Specifies that the key never expires after it becomes valid.
to
: Specifies the end time and date.
end-time
: Specifies the end time in the HH:MM:SS format. The value range for this argument is 0:0:0
to 23:59:59.
end-date
: Specifies the end date in the MM/DD/YYYY or YYYY/MM/DD format. The value range for
YYYY is 2000 to 2035.
Usage guidelines
A key becomes a valid send key when the following requirements are met:
•
A key string has been configured.
•
An authentication algorithm has been specified.
•
The system time is within the specified sending lifetime.
To make sure only one key in a keychain is used at a time to authenticate packets to a peer, set
non-overlapping sending lifetimes for the keys in the keychain.
Examples
# Set the sending lifetime for key 1 of keychain
abc
in absolute time mode.
<Sysname> system-view
[Sysname] keychain abc mode absolute
[Sysname-keychain-abc] key 1
[Sysname-keychain-abc-key-1] send-lifetime utc 12:30 2015/1/21 to 18:30 2015/1/21
tcp-algorithm-id
Use
tcp-algorithm-id
to set an algorithm ID for a TCP authentication algorithm.
Use
undo tcp-algorithm-id
to restore the default.
Syntax
tcp-algorithm-id
{
hmac-md5
|
md5
}
algorithm-id
undo tcp-algorithm-id
{
hmac-md5
|
md5
}
Default
The algorithm ID is 3 for the MD5 authentication algorithm, and is 5 for the HMAC-MD5
authentication algorithm.
Views
Keychain view
Predefined user roles
network-admin
Содержание FlexNetwork 7500 Series
Страница 350: ...335 Related commands display port security port security enable ...
Страница 379: ...364 Sysname system view Sysname keychain abc mode absolute Sysname keychain abc tcp kind 252 ...
Страница 519: ...504 Related commands display ssh2 algorithm ssh2 algorithm cipher ssh2 algorithm key exchange ssh2 algorithm mac ...