SROS Command Line Interface Reference Guide
Crypto Map IKE Command Set
5991-2114
© Copyright 2007 Hewlett-Packard Development Company, L.P.
1229
commit-bit
Use the
commit-bit
command to set the commit-bit in the Internet Security Association and Key
Management Protocol (ISAKMP) header when sending the second message of quick mode on an IPSec
tunnel negotiation. Use the
no
form of this command to disable this feature.
Syntax Description
No subcommands.
Default Values
By default, the commit-bit will be used.
Functional Notes
As an extra security measure, the commit-bit can be set by the responder of a quick mode negotiation to
force the initiator to wait for the fourth message of quick mode before bringing up its IPSec security
associations (SA's). By default, this feature is enabled on all SROS routers. Some vendors, however, may
have incorrect implementations of the commit-bit that do not interoperate well with SROS routers. In that
case, the commit-bit should be disabled on all crypto maps that have a peer which does not support the
commit-bit.
Usage Example
The following example disables the use of commit-bit:
ProCurve(config-crypto-map)#
no commit-bit
The following example displays a configuration with the commit-bit disabled:
ip crypto
!
crypto ike policy 100
initiate main
respond main
local-id address 10.10.10.1
peer 192.168.1.1
attribute 2
encryption aes-256-cbc
authentication pre-share
lifetime 3600
!
crypto ike remote-id address 10.10.10.1 preshared-key procurve ike-policy 100 crypto map VPN 10
no-mode-config no-xauth
Содержание ProCurve Secure 7102dl
Страница 2: ......
Страница 3: ...SROS Command Line Interface Reference Guide Software Version J 08 03 September 2007 61195880L1 35H ...
Страница 1454: ......