crypto-map
10-9
Usage Guidelines
WS5100(config-crypto-map)#set peer (name)
If no peer IP address is configured, the manual crypto map is not valid and not complete.
A peer IP address is required for manual crypto maps. To change the peer IP address, the
no set peer command must be issued first; then the new peer IP address can be configured.
WS5100(config-crypto-map)#set pfs
If left at the default setting, no perfect forward secrecy (PFS) is used during IPSec SA key
generation. If PFS is specified, the specified Diffie-Hellman Group exchange is used for the
initial (and all subsequent) key generation. This means no data linkage between prior keys
and future keys.
WS5100(config-crypto-map)#set security-association lifetime
(kilobytes|seconds)
Values can be entered in both kilobytes and seconds. Whichever limit is reached first, ends
the security association.
WS5100(config-crypto-map)#set session-key
(inbound|outbound)(ah|esp)
WS5100(config-crypto-map)#set session-key (inbound|outbound) ah
<hexkey data>
WS5100(config-crypto-map)#set session-key (inbound|outbound) esp
<SPI> cipher <hexdata key> authenticator <hexkey data>
inbound/outbound
(ah|esp)
Defines encryption keys for inbound/outbound traffic
•
ah –
Authentication header protocol
• <256-4294967295> –
Security Parameter
Index
(SPI) for the security association
•
esp –
Encapsulating security payload protocol
• <256-4294967295> – Derfines the security
parameter Index
• cipher – Specify encryption/decryption
key
•
authenticator <hex key data> –
Specify
an authentication key
transformset <name>
Use the set transform-set command to assign a transform-
set to a crypto map.
Содержание WS5100 Series
Страница 1: ...M WS5100 Series Switch CLI Reference Guide ...
Страница 14: ...WS5100 Series Switch CLI Reference Guide xviii ...
Страница 28: ...WS5100 Series Switch CLI Reference Guide TOC 14 ...
Страница 40: ...WS5100 Series Switch CLI Reference Guide 1 12 ...
Страница 132: ...WS5100 Series Switch CLI Reference Guide 3 10 ...
Страница 164: ...WS5100 Series Switch CLI Reference Guide 4 32 ...
Страница 240: ...WS5100 Series Switch CLI Reference Guide 6 10 ...
Страница 258: ...WS5100 Series Switch CLI Reference Guide 9 4 ...
Страница 270: ...WS5100 Series Switch CLI Reference Guide 10 12 ...
Страница 332: ...WS5100 Series Switch CLI Reference Guide 14 22 ...
Страница 344: ...WS5100 Series Switch CLI Reference Guide 15 12 ...
Страница 482: ...WS5100 Series Switch CLI Reference Guide 20 64 ...
Страница 491: ......
Страница 492: ...MOTOROLA INC 1303 E ALGONQUIN ROAD SCHAUMBURG IL 60196 http www motorola com 72E 103896 01 Revision A January 2008 ...