Configuring TCP Keychain Options
- Enter global configuration mode.
- Create a TCP keychain.The command places the ICX device in TCP keychain configuration mode, where TCP authentication options are available.
- Configure a key by specifying a key identifier.
- Specify the authentication algorithm to be used.
- Specify whether TCP packet
segments received with mismatched AO settings will be accepted or
discarded.The example configures the ICX device to discard TCP segments with mismatched AO settings.Note: By default, mismatched TCP segments are accepted.
- Specify whether the MAC calculation includes all TCP options.
- Configure the ID to be used in
transmitted TCP packets. Enter a decimal value from 0 through 255.Note: This value must match the receive-id configured at the other end of the TCP connection.
- Configure the ID to be compared
to the key identifier in TCP packet segments received by the ICX device. Enter a
decimal value from 0 through 255. Note: This value must match the send-id configured at the other end of the TCP connection.
- Configure the time period during
which the key on a keychain is active and can be received as a valid key. The end time can be configured as one of the following options: duration in seconds, infinite, or date and time format (mm-dd-yy hh:mm:ss). The maximum lifetime in seconds is 2147483648.The following example configures the accept lifetime of key 1 to start on November 10, 2019 at 10:10 am and 10 seconds and to end 10,000 seconds later.
- Configure the time period during
which the key on a keychain becomes active and is valid to be sent. The end time can be configured as one of the following options: duration in seconds, infinite, or date and time format (mm-dd-yy hh:mm:ss).The following example configures key 1 to be active and available for sending from November 10, 2019 at 10:10 am and 10 seconds, with no expiration.
- (Optional) Enable logging of TCP authentication option messages.
- (Optional) Verify the TCP keychain configuration.
device(config)# show keychain name mykeychain Keychain: mykeychain TCP-AO: TRUE Key-id : 1 Auth-Algorithm: aes-128-cmac Key-String : ******* Send-id : 1 Recv-id : 2 include-tcp-options : YES accept-ao-mismatch : NO Send Lifetime:- Start : 11-10-19 10:10:10 End : Infinite Active : No TimeToActive: 27583321 sec Timezone : Local Accept Lifetime:- Start : 11-10-19 10:10:10 End : 10000 Active : No TimeToActive: 27583321 sec Timezone : Local
The following example configures a TCP keychain and underlying options.
device# configure terminal device(config)# keychain mykeychain tcp device(config-keychain-tcp-mykeychain)# key 1 device(config-keychain-tcp-mykeychain-key-1)# authentication-algorithm aes-128-cmac device(config-keychain-tcp-mykeychain-key-1)# no accept-ao-mismatch device(config-keychain-tcp-mykeychain-key-1)# include-tcp-options device(config-keychain-tcp-mykeychain-key-1)# send-id 1 device(config-keychain-tcp-mykeychain-key-1)# recv-id 2 device(config-keychain-tcp-mykeychain-key-1)# accept-lifetime start 11-10-19 10:10:10 end 10000 device(config-keychain-tcp-mykeychain-key-1)# send-lifetime start 11-10-19 10:10:10 end infinite device(cconfig-keychain-tcp-mykeychain-key-1)# exit device(config-keychain-tcp-mykeychain)# exit