Configuring TCP Keychain Options

  1. Enter global configuration mode.
    device# configure terminal
    device(config)#
  2. Create a TCP keychain.
    device(config)# keychain mykeychain tcp
    device(config-keychain-tcp-mykeychain)#
    
    The command places the ICX device in TCP keychain configuration mode, where TCP authentication options are available.
  3. Configure a key by specifying a key identifier.
    device(config-keychain-tcp-mykeychain)# key-id 1
  4. Specify the authentication algorithm to be used.
    device(config-keychain-tcp-mykeychain-key-1)# authentication-algorithm aes-128-cmac
    Note: The hmac-sha-1 algorithm is also available for TCP authentication.
    Note: Use the no authentication-algorithm aes-128-cmac command to remove the algorithm.
  5. Specify whether TCP packet segments received with mismatched AO settings will be accepted or discarded.
    device(config-keychain-tcp-mykeychain-key-1)# no accept-ao-mismatch
     
    The example configures the ICX device to discard TCP segments with mismatched AO settings.
    Note: By default, mismatched TCP segments are accepted.
  6. Specify whether the MAC calculation includes all TCP options.
    device(config-keychain-tcp-mykeychain-key-1)# include-tcp-options
     
    Note: By default, all TCP options are included in the MAC calculation. To include only the TCP AO options in the calculation, use the no include-tcp-options command.
  7. Configure the ID to be used in transmitted TCP packets. Enter a decimal value from 0 through 255.
    device(config-keychain-tcp-mykeychain-key-1)# send-id 1 
    Note: This value must match the receive-id configured at the other end of the TCP connection.
  8. Configure the ID to be compared to the key identifier in TCP packet segments received by the ICX device. Enter a decimal value from 0 through 255.
    device(config-keychain-tcp-mykeychain-key-1)# recv-id 2 
     
    Note: This value must match the send-id configured at the other end of the TCP connection.
  9. Configure the time period during which the key on a keychain is active and can be received as a valid key.
    The end time can be configured as one of the following options: duration in seconds, infinite, or date and time format (mm-dd-yy hh:mm:ss). The maximum lifetime in seconds is 2147483648.
    The following example configures the accept lifetime of key 1 to start on November 10, 2019 at 10:10 am and 10 seconds and to end 10,000 seconds later.
    device(config-keychain-tcp-mykeychain-key-1)# accept-lifetime start 11-10-19 10:10:10 end 10000 
  10. Configure the time period during which the key on a keychain becomes active and is valid to be sent.
    The end time can be configured as one of the following options: duration in seconds, infinite, or date and time format (mm-dd-yy hh:mm:ss).
    The following example configures key 1 to be active and available for sending from November 10, 2019 at 10:10 am and 10 seconds, with no expiration.
    device(config-keychain-tcp-mykeychain-key-1)# send-lifetime start 11-10-19 10:10:10 end infinite 
  11. (Optional) Enable logging of TCP authentication option messages.
    device(config-keychain-tcp-mykeychain-key-1)# exit
    device(config-keychain-tcp-mykeychain)# exit
    device(config)# logging enable tcp-ao  
  12. (Optional) Verify the TCP keychain configuration.
    device(config)# show keychain name mykeychain
    Keychain: mykeychain
    TCP-AO: TRUE
    Key-id : 1
    Auth-Algorithm: aes-128-cmac
    Key-String : *******
    Send-id : 1
    Recv-id : 2
    include-tcp-options : YES
    accept-ao-mismatch : NO
    Send Lifetime:-
    Start : 11-10-19 10:10:10 End : Infinite
    Active : No TimeToActive: 27583321 sec
    Timezone : Local
    Accept Lifetime:-
    Start : 11-10-19 10:10:10  End : 10000
    Active : No TimeToActive: 27583321 sec
    Timezone : Local
    Note: You can use the show keychain tcp or the show keychain name name command to verify the TCP keychain settings.

The following example configures a TCP keychain and underlying options.

device# configure terminal
device(config)# keychain mykeychain tcp
device(config-keychain-tcp-mykeychain)# key 1
device(config-keychain-tcp-mykeychain-key-1)# authentication-algorithm aes-128-cmac
device(config-keychain-tcp-mykeychain-key-1)# no accept-ao-mismatch
device(config-keychain-tcp-mykeychain-key-1)# include-tcp-options
device(config-keychain-tcp-mykeychain-key-1)# send-id 1
device(config-keychain-tcp-mykeychain-key-1)# recv-id 2
device(config-keychain-tcp-mykeychain-key-1)# accept-lifetime start 11-10-19 10:10:10 end 10000
device(config-keychain-tcp-mykeychain-key-1)# send-lifetime start 11-10-19 10:10:10 end infinite
device(cconfig-keychain-tcp-mykeychain-key-1)# exit
device(config-keychain-tcp-mykeychain)# exit