HP StorageWorks 8/20q HP StorageWorks 8/20q Fibre Channel Switch Command Line - Page 36

Modifying a user-defined association, required entry.

Page 36 highlights

Modifying a user-defined association To modify an existing user-defined association, enter the ipsec association edit command in an Admin session and an Ipsec Edit session as shown in the following example. An asterisk (*) indicates a required entry. 8/20q FC Switch (admin-ipsec) #> ipsec association edit h2h-sh-sa A list of attributes with formatting and current values will follow. Enter a new value or simply press the ENTER key to accept the current value. To remove a value for an optional attribute, use 'n'. If you wish to terminate this process before reaching the end of the list press 'q' or 'Q' and the ENTER key to do so. Current Values: Description . . EncryptionKey Host-to-host:switch->host 123456789012345678901234 New Value (press ENTER to not specify value, 'q' to quit, 'n' for none): Description (string value, 0-127 bytes) : *SourceAddress (hostname, IPv4, or IPv6 Address) : *DestinationAddress (hostname, IPv4, or IPv6 Address) : *Protocol (1=esp, 2=esp-old, 3=ah, 4=ah-old) : ah *SPI (decimal value, 256-4294967295) : Authentication (select an authentication algorithm) 1=hmac-md5 (16 byte key) 2=hmac-sha1 (20 byte key) 3=hmac-sha256 (32 byte key) 4=aes-xcbc-mac (16 byte key) authentication algorithm choice : *AuthenticationKey (quotes string or raw hex bytes) : *Encryption (select an encryption algorithm) 1=des-cbc (8 byte key) 2=3des-cbc (24 byte key) 3=null (0 byte key) 4=blowfish-cbc (5-56 byte key) 5=aes-cbc (16/24/32 byte key) 6=twofish-cbc (32 byte key) encryption algorithm choice : *EncryptionKey (quoted string or raw hex bytes) : The security association has been edited. This configuration must be saved with the 'ipsec save' command before it can take effect, or to discard this configuration use the 'ipsec cancel' command. 8/20q FC Switch (admin-ipsec) #> ipsec save The IPsec configuration will be saved and activated. Please confirm (y/n): [n] y 36 Network configuration

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332

36
Network configuration
Modifying a user-defined association
To modify an existing user-defined association, enter the
ipsec association edit
command in an
Admin session and an Ipsec Edit session as shown in the following example. An asterisk (*) indicates a
required entry.
8/20q FC Switch (admin-ipsec) #> ipsec association edit h2h-sh-sa
A list of attributes with formatting and current values will follow.
Enter a new value or simply press the ENTER key to accept the current value.
To remove a value for an optional attribute, use ā€™nā€™.
If you wish to terminate this process before reaching the end of the list
press 'q' or 'Q' and the ENTER key to do so.
Current Values:
Description
Host-to-host:switch->host
.
.
EncryptionKey
123456789012345678901234
New Value (press ENTER to not specify value, 'q' to quit, 'n' for none):
Description
(string value, 0-127 bytes)
:
*SourceAddress
(hostname, IPv4, or IPv6 Address)
:
*DestinationAddress
(hostname, IPv4, or IPv6 Address)
:
*Protocol
(1=esp, 2=esp-old, 3=ah, 4=ah-old)
: ah
*SPI
(decimal value, 256-4294967295)
:
Authentication
(select an authentication algorithm)
1=hmac-md5
(16 byte key)
2=hmac-sha1
(20 byte key)
3=hmac-sha256
(32 byte key)
4=aes-xcbc-mac
(16 byte key)
authentication algorithm choice
:
*AuthenticationKey
(quotes string or raw hex bytes)
:
*Encryption
(select an encryption algorithm)
1=des-cbc (8 byte key)
2=3des-cbc (24 byte key)
3=null (0 byte key)
4=blowfish-cbc (5-56 byte key)
5=aes-cbc (16/24/32 byte key)
6=twofish-cbc (32 byte key)
encryption algorithm choice
:
*EncryptionKey
(quoted string or raw hex bytes)
:
The security association has been edited.
This configuration must be saved with the 'ipsec save' command
before it can take effect, or to discard this configuration
use the 'ipsec cancel' command.
8/20q FC Switch (admin-ipsec) #> ipsec save
The IPsec configuration will be saved and activated.
Please confirm (y/n): [n] y