crypto isakmp policy (2024)

crypto isakmp policy <priority>

authentication {pre-share|rsa-sig|ecdsa-256|ecdsa-384}

disable

enable [bypass|secret]

encryption {3DES|AES128|AES192|AES256|DES}

group {1|2|14|19|20}

hash {md5|sha|sha1-96|sha2-256-128|sha2-384-192}

prf {PRF-HMAC-MD5|PRF-HMAC-SHA1|PRF-HMAC-SHA256|PRF-HMAC-SHA384}

lifetime <seconds>

no disable

version {v1|v2}

Description

This command configures Internet Key Exchange (IKE) policy parameters for the Internet Security Association and Key Management Protocol (ISAKMP). To define settings for a ISAKMP policy, issue the command crypto isakmp policy <priority> then press Enter. The CLI will enter config-isakmp mode, which allows you to configure the policy values.

Parameter

Description

<priority>

Specifies a number from 1 to 10,000 to define a priority level for the policy. The higher the number, the higher the priority level.

authentication

Configures the IKE authentication method:

  • pre-share: Preshared key
  • rsa-sig: RSAsignatures
  • ecdsa-256: ECDSA-256-bit signatures
  • ecdsa-384: ECDSA-384-bit signatures

disable

Disables the IKE policy.

enable [bypass|secret]

Enables the IKE policy using the bypass or secret. Bypass prompts for the enable mode login and password. Secret prompts for the enable password.

encryption

Configures the IKE encryption algorithm:

  • 3DES: 168-bit 3DES-CBC encryption algorithm
  • AES128: 128-bit AES-CBC encryption algorithm
  • AES192: 192-bit AES-CBC encryption algorithm
  • AES256: 256-bit AES-CBC encryption algorithm
  • DES: 56-bit DES-CBCencryption algorithm

group

Configures the IKE Diffie Hellman group:

  • 1: 768-bit Diffie Hellman prime modulus group. This is the default group setting.
  • 2: 1024-bit Diffie Hellman prime modulus group
  • 14: 2048-bit Diffie Hellman DDH prime modulus group
  • 19: 256-bit random Diffie Hellman ECP modulus group
  • 20: 384-bit random Diffie Hellman ECP modulus group

hash

Configures the IKEhash algorithm:

  • md5: MD5 (HMAC variant) hash algorithm
  • sha: SHA1-160 (HMAC variant) hash algorithm
  • sha1-96: SHA1-96 (HMAC variant) hash algorithm
  • sha2-256-128: SHA2-256-128 (HMAC variant) hash algorithm
  • sha2-384-192: SHA2-384-192 (HMAC variant) hash algorithm

prf

Sets one of the following pseudo-random function (PRF) values for an IKEv2 policy:

  • PRF-HMAC-MD5 (default):MD5 (HMAC variant) PRF
  • PRF-HMAC-SHA1: SHA1-160 (HMAC variant) PRF
  • PRF-HMAC-SHA256:SHA2-256 PRF
  • PRF-HMAC-SHA384: SHA2-384 PRF

lifetime <seconds>

Specifies the lifetime of the IKE security association (SA), from 300 - 86400 seconds.

no disable

Disables the IKE policy.

version

Specifies the version of IKE protocol for the IKE policy:

  • v1: IKEv1
  • v2: IKEv2

Example

The following command configures the RSAsignature authentication method for the given IKE policy:

(host) [mynode] (config) #crypto isakmp policy 1

(host) [mynode] (config-isakmp) #authentication rsa-sig

Key:*******Re-Type Key:*******

Related Commands

Command

Description

show crypto isakmp

Displays IKEpolicies configured for ISAKMP.

Command History

Release

Modification

ArubaOS 8.0.0.0

Command introduced.

Command Information

Platforms

License

Command Mode

All platforms

The following settings require the Advanced Cryptogram (ACR) license:

  • hash algorithm: SHA-256-128, SHA-384-192
  • Diffie-Hellman (DH) Groups: 19 and 20
  • Pseudo-Random Function (PRF): PRF-HMAC-SHA256, PRF-HMAC-SHA384
  • Authentication: ecdsa-256 and ecdsa-384

All other parameters are supported in the base OS.

Config mode on Mobility Conductor.

crypto isakmp policy (2024)
Top Articles
The Role of HR in Driving Sustainability: A Brief Overview
Is algorithmic trading profitable?
Oriellys Bad Axe
Sef2 Lewis Structure
9 Cara Merawat Router WiFi untuk Internet yang Cepat dan Stabil
Kian And Jc Seatgeek Promo Code
Meshuggah Bleed Tab
Oro probablemente a duna Playa e nomber Oranjestad un 200 aña pasa, pero Playa su historia ta bay hopi mas aña atras
Gtl Visit Me Alameda
Prestige Home Designs By American Furniture Galleries
Craigslist Akron Canton Ohio
30 Chinese New Year Recipes That Will Bring You Good Fortune This Year
Cookie Run Kingdom Wiki Characters
Dexter Gomovies
Dylan Dreyer Yellow Dress Today
Mail Healthcare Uiowa
selena gomez en ropa interior
Creed 3 Showtimes Near Southeast Cinemas Alamance Crossing Stadium 16
Cranes Lane, Ormskirk L40 3 bed end of terrace house to rent - £1,495 pcm (£345 pw)
(6302Z) Rillenkugellager einreihig 2Z Deckscheibe beidseitig, Außen-Ø 42mm, Innen-Ø 15mm, Breite 13mm von NTN
Whisk Recipe Calculator
Cayucos Craigslist
159R Bus Schedule Pdf
The Salem News Obituaries
Qdoba Gull Road
Loss Payee And Lienholder Addresses And Contact Information Updated Daily Free List Bank Of America
Jesus Revolution Showtimes Near Amc Classic Findlay 12
Oppenheimer Showtimes Near Cinemark Denton
Tuscora Park in New Philadelphia | Ohio - on FamilyDaysOut.com
Jessica Ann Ussery Wiki
Kytty_Keeet
Walmart Tire And Lube Center Near Me
Copper Grooming Report
Methodist Laborworkx
Maine Activity Partners
Back Pages Chattanooga
Black Panther 2 Showtimes Near Epic Theatres Of Palm Coast
Lady Eloise Cordelia Gordon-Lennox
He bought a cruise ship on Craigslist and spent over $1 million restoring it. Then his dream sank
Skroch Funeral Chapel Obituaries
The Culhanes Of Cornfield County
Humanplex
'Saw X': Release Date, Cast, Trailer, and Everything We Know So Far
Bofa Drive Thru Near Me
Blox Fruits: Best Fruits Tier List (Update 21) - Item Level Gaming
Anthem Bcbs Otc Catalog 2022
Service Flat / Unsinn ?
Splunk Append Search
Netid.unm.edu
Walking the Grænagil-Laugavegur loop - I Am a Polar Bear
Trinidad And Tobago Passport Renewal In Usa
Latest Posts
Article information

Author: Rubie Ullrich

Last Updated:

Views: 5834

Rating: 4.1 / 5 (72 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Rubie Ullrich

Birthday: 1998-02-02

Address: 743 Stoltenberg Center, Genovevaville, NJ 59925-3119

Phone: +2202978377583

Job: Administration Engineer

Hobby: Surfing, Sailing, Listening to music, Web surfing, Kitesurfing, Geocaching, Backpacking

Introduction: My name is Rubie Ullrich, I am a enthusiastic, perfect, tender, vivacious, talented, famous, delightful person who loves writing and wants to share my knowledge and understanding with you.