HP 8/20q HP StorageWorks 8/20q Fibre Channel Switch Command Line Interface Gui - Page 162

ipsec association, Table 13 Association configuration parameters

Page 162 highlights

ipsec association Description Creates and manages associations in the Security Association database. Authority Admin session and an Ipsec Edit session Syntax ipsec association copy [association_source] [association_destination] create [association] delete [association] edit [association] list [association] rename [association_old] [association_new] Operands copy [association_source] [association_destination] Creates a new association named [association_destination] and copies the configuration into it from the association given by [association_source]. [association_destination] must not begin with DynamicSA_, which is reserved for dynamic associations. You must enter the Ipsec Save command afterwards to save your changes. create [association] Creates an association with the name given by [association]. An association name must begin with a letter and be no longer than 32 characters. Valid characters are alphanumeric, _, $, ^, and -. The Security Association database supports a maximum of 512 user-defined associations. You must enter the Ipsec Save command afterwards to save your changes. Table 13 describes the association configuration parameters. Table 13 Association configuration parameters Parameter Description SourceAddress DestinationAddress Protocol SPI Authentication AuthenticationKey Description Description of the association indicating its purpose or the types of connections which it secures. IP address (version 4 or 6) or DNS host name of the host, switch, or gateway from which data originates IP address (version 4 or 6) or DNS host name of the host, switch, or gateway receiving data. If you specified an IP address for the SourceAddress, the DestinationAddress must use the same IP version format. IP security protocol to be used to process data. The protocol can be one of the following: • Encapsulated Security Payload-RFC 2406 (esp) • Encapsulated Security Payload-RFC 1827 (esp-old) • Authentication Header- RFC 2402 (ah) • Authentication Header-RFC 1826 (ah-old) Security parameters index number in the range 256-4,294,967,295 Algorithm to use to authenticate the source or destination. The authentication algorithm can be one of the following: • HMAC-MD5 • HMAC-SHA1 • HMAC-SHA256 • AES-XCBC-MAC Key string to use for authentication such as "12345678901234567890" 162 Command Reference

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330

162
Command Reference
ipsec association
Description
Creates and manages associations in the Security Association database.
Authority
Admin session and an Ipsec Edit session
Syntax
ipsec association
copy [association_source] [association_destination]
create [association]
del
ete [association]
edit [association]
list [association]
rename [association_old] [association_new]
Operands
copy [association_source] [association_destination]
Creates a new association named [association_destination] and copies the configuration into it
from the association given by [association_source]. [association_destination] must not begin with
DynamicSA_
, which is reserved for dynamic associations. You must enter the Ipsec Save
command afterwards to save your changes.
create [association]
Creates an association with the name given by [association]. An association name must begin
with a letter and be no longer than 32 characters. Valid characters are alphanumeric, _, $, ^,
and -. The Security Association database supports a maximum of 512 user-defined associations.
You must enter the Ipsec Save command afterwards to save your changes.
Table 13
describes
the association configuration parameters.
Table 13
Association configuration parameters
Parameter
Description
Description
Description of the association indicating its purpose or the types of
connections which it secures.
SourceAddress
IP address (version 4 or 6) or DNS host name of the host, switch, or
gateway from which data originates
DestinationAddress
IP address (version 4 or 6) or DNS host name of the host, switch, or
gateway receiving data. If you specified an IP address for the
SourceAddress
, the
DestinationAddress
must use the same
IP version format.
Protocol
IP security protocol to be used to process data. The protocol can be
one of the following:
Encapsulated Security Payload–RFC 2406 (esp)
Encapsulated Security Payload–RFC 1827 (esp-old)
Authentication Header– RFC 2402 (ah)
Authentication Header–RFC 1826 (ah-old)
SPI
Security parameters index number in the range 256–4,294,967,295
Authentication
Algorithm to use to authenticate the source or destination. The
authentication algorithm can be one of the following:
HMAC-MD5
HMAC-SHA1
HMAC-SHA256
AES-XCBC-MAC
AuthenticationKey
Key string to use for authentication such as
"12345678901234567890"