530
aes-cbc-192
: Uses the AES algorithm in CBC mode as the encryption algorithm. The AES algorithm
uses a 192-bit key for encryption.
aes-cbc-256
: Uses the AES algorithm in CBC mode as the encryption algorithm. The AES algorithm
uses a 256-bit key for encryption.
des-cbc
: Uses the DES algorithm in CBC mode as the encryption algorithm. The DES algorithm
uses a 56-bit key for encryption.
Examples
# Use the 128-bit AES in CBC mode as the encryption algorithm for IKE proposal 1.
<Sysname> system-view
[Sysname] ike proposal 1
[Sysname-ike-proposal-1] encryption-algorithm aes-cbc-128
Related commands
display ike proposal
exchange-mode
Use
exchange-mode
to select an IKE negotiation mode for phase 1.
Use
undo exchange-mode
to restore the default.
Syntax
In non-FIPS mode:
exchange-mode
{
aggressive
|
main
}
undo exchange-mode
In FIPS mode:
exchange-mode main
undo exchange-mode
Default
Main mode is used for phase 1.
Views
IKE profile view
Predefined user roles
network-admin
Parameters
aggressive
: Specifies the aggressive mode.
main
: Specifies the main mode.
Usage guidelines
As a best practice, specify the
aggressive
mode at the local end if the following conditions are met:
•
The local end, for example, a dialup user, obtains an IP address automatically.
•
Pre-shared key authentication is used.
Examples
# Specify that IKE negotiation operates in main mode.
<Sysname> system-view
[Sysname] ike profile 1
Summary of Contents for FlexNetwork MSR Series
Page 1005: ...987 ...