VPN
Issue 1 January 2008
1211
Related Commands
set security-association lifetime
set pfs
Use the
set pfs
command to specify whether each IKE phase 2 negotiation will employ
Perfect Forward Secrecy (PFS), and if yes, which Diffie-Hellman group to employ. PFS ensures
that even if someone were to discover the long-term secret(s), the attacker would not be able to
recover the session keys, both past and present. In addition, the discovery of a session key
compromises neither the long-term secrets nor the other session keys.
Use the
no
form of the command to disable PFS for IKE phase 2 (default setting).
Syntax
[no] set pfs [group1 | group2 | group5 | group14]
Note:
Note:
Using
set pfs
with no parameters sets the PFS group to 1.
Parameters
User Level
read-write
Context
crypto ipsec transform-set
Parameter
Description
Possible
Values
Default
Value
group1
Keyword specifying that IKE employ the
768-bit Diffie-Hellman prime modulus group
group2
Keyword specifying that IKE employ the
1,024-bit Diffie-Hellman prime modulus group
group5
Keyword specifying that IKE employ the
1536-bit Diffie-Hellman prime modulus group
group14
Keyword specifying that IKE employ the
2048-bit Diffie-Hellman prime modulus group
Summary of Contents for G450 Manager
Page 1: ...Avaya G450 CLI Reference 03 602056 Issue 1 January 2008 ...
Page 32: ...Contents 32 Avaya G450 CLI Reference ...
Page 38: ...About this Book 38 Avaya G450 CLI Reference ...
Page 154: ...Roadmap 154 Avaya G450 CLI Reference ...
Page 1304: ...CLI Commands WFVQ Weighted Fair VoIP Queueing 1304 Avaya G450 CLI Reference ...