ADTRAN Stub Routing Spezifikationen Seite 280

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 568
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 279
Crypto Map IKE Command Set Command Reference Guide
280 © 2003 ADTRAN, Inc. 61950860L1-35D
set pfs [group1 | group2]
Use the set pfs command to choose the type of perfect forward secrecy (if any) that will be required during
IPSec negotiation of security associations for this crypto map. Use the no form of this command to require
no PFS.
Syntax Description
group1
IPSec is required to use Diffie-Hellman Group 1 (768-bit modulus) exchange
during IPSec SA key generation.
group2
IPSec is required to use Diffie-Hellman Group 2 (1024-bit modulus) exchange
during IPSec SA key generation.
Default Values
By default, no PFS will be used during IPSec SA key generation.
Command Modes
(config-crypto-map)# Crypto Map IKE Configuration Mode
Command History
Release 4.1 Command was introduced
Functional Notes
If left at the default setting, no perfect forward secrecy (PFS) will be used during IPSec SA key generation. If
PFS is specified, then the specified Diffie-Hellman Group exchange will be used for the initial and all
subsequent key generation, thus providing no data linkage between prior keys and future keys.
Usage Examples
The following example specifies use of the Diffie-Hellman Group 1 exchange during IPSec SA key generation:
(config-crypto-map)#
set pfs group 1
Seitenansicht 279
1 2 ... 275 276 277 278 279 280 281 282 283 284 285 ... 567 568

Kommentare zu diesen Handbüchern

Keine Kommentare