encryption-algorithm

Configures an encryption algorithm to protect data traffic for an IPsec proposal.
Syntax
encryption-algorithm{aes-gcm-256|aes-gcm-128}
no encryption-algorithm{aes-gcm-256|aes-gcm-128}
Command Default

The default encryption algorithm for an IPsec proposal is AES-GCM-256.

Parameters
aes-gcm-256
Specifies that the 256-bit advanced encryption standard algorithm in Galois counter mode is supported for Encapsulating Security Payload (ESP) encryption.
aes-gcm-128
Specifies that the 128-bit advanced encryption standard algorithm in Galois counter mode is supported for ESP encryption.
Modes

IPsec proposal configuration mode

Usage Guidelines

Multiple encryption algorithms may be configured for an IPsec proposal.

For an IPsec tunnel to come up successfully, IPsec peer devices must be configured with a common encryption algorithm.

When dual mode is configured on both the local and remote peers, AES-GCM-256 is automatically selected for encryption and decryption.

When dual mode is not configured on both the local and remote peers, the algorithm that is configured on both peers is automatically selected for encryption and decryption.

When only one encryption algorithm is configured for an IPsec proposal, removing it restores the default configuration.

The no form of the command removes the specified encryption algorithm configuration.

Examples

The following example shows how to configure the AES-GCM-128 encryption algorithm for an IPsec proposal named ipsec_prop.

device(config)# ipsec proposal ipsec_prop
device(config-ipsec-proposal-ipsec_prop)# encryption-algorithm aes-gcm-128
History
Release version Command history
08.0.50 This command was introduced.