ipsec proposal

Creates an IP security (IPsec) proposal and enters IPsec proposal configuration mode.
Syntax
ipsec proposal name
Parameters
name
Specifies the name of an IPsec proposal.
Modes

Global configuration mode

Usage Guidelines

An IPsec proposal defines an encryption algorithm, encapsulation mode, and transform set used to negotiate with a data path peer. An IPsec proposal is activated by attaching it to an IPsec profile.

There is a default IPsec proposal (def-ipsec-prop) that is defined at IPsec initialization and has the following settings:

  • transform: ESP
  • encapsulation-mode: Tunnel
  • encryption-algorithm: AES-GCM-256

Use the ipsec proposal command to configure any additional IPsec proposals.

The no form of the command removes any IPsec proposal configuration other than the default IPsec proposal configuration.

The default IPsec proposal cannot be removed.

Examples

The following example creates an IPSec proposal named ipsec_proposal and enters IPsec proposal configuration mode for the proposal .

device(config)# ipsec proposal ipsec_proposal
device(config-ipsec-proposal-ipsec_proposal)#
History
Release version Command history
08.0.50 This command was introduced.