Important: The commands or keywords/variables that are available are dependent on platform type, product version, and installed license(s).
• encryption: Default algorithm for the IKEv2 IKE SA is AES-CBC-128.
• group: Default Diffie-Hellman group is Group 2.
• hmac: Default IKEv2 IKE SA hashing algorithm is SHA1-96.
• lifetime: Default lifetime for SAs derived from this transform-set is 86400 seconds.
• prf: Default PRF for the IKEv2 IKE SA is SHA1.lifetime seclifetime secSets the value of the timeout parameter. sec must be an integer from 60 to 86400.The prf command is used for generating keying material for all the cryptographic algorithms used in both the IKE_SA and the CHILD_SAs.
|
| Cisco Systems Inc. |
| Tel: 408-526-4000 |
| Fax: 408-527-0883 |