encryption-algorithm
encryption-algorithm
{
aes-gcm-256
|
aes-gcm-128
}
no encryption-algorithm
{
aes-gcm-256
|
aes-gcm-128
}
The default encryption algorithm for an IPsec proposal is AES-GCM-256.
IPsec proposal configuration mode
Multiple encryption algorithms may be configured for an IPsec proposal.
For an IPsec tunnel to come up successfully, IPsec peer devices must be configured with a common encryption algorithm.
RUCKUS ICX 7450 supports dual mode for encryption and decryption. Dual mode is set when both the AES-GCM-128 and AES-GCM-256 algorithms are set for the same IPSec proposal (no further configuration is needed to establish dual mode).
When dual mode is configured on both the local and remote peers, AES-GCM-256 is automatically selected for encryption and decryption.
When dual mode is not configured on both the local and remote peers, the algorithm that is configured on both peers is automatically selected for encryption and decryption.
When only one encryption algorithm is configured for an IPsec proposal, removing it restores the default configuration.
The
no form of the command removes the specified encryption algorithm configuration.
| Release version | Command history |
|---|---|
| 08.0.50 | This command was introduced. |