keychain tcp
No keychain is configured by default.
TCP Authentication Options (AO):
[no] accept-ao-mismatch- Determines whether the ICX device accepts or denies TCP segments with a mismatch in TCP-AO support between the TCP peers. By default, mismatched segments are accepted. When the option is disabled, TCP-AO packets with a mismatch are discarded.
[no] authentication-algorithmaes-128-cmac- Configures the aes-128-cmac algorithm for TCP authentication. The algorithm hmac-sha-1 is also supported.
[no] include-tcp-options- Determines whether all TCP options are included in the Message Authentication Code (MAC) calculation. By default, all TCP options are included. When the no form of the command is configured, only the TCP-AO option is included in the MAC calculation.
[no] recv-idid- Configures the identifier to be compared with the key identifier received in a TCP segment. Valid values are 0 through 255. The no form of the command removes the identifier.
Global configuration mode
The keychain
keychain-name
tcp command is not supported for ICX 7150 devices.
A maximum of 64 keychains can be configured, including TCP keychains and other types.
The keychain
keychain-name
tcp command takes the configuration to the TCP keychain
configuration mode, in which the listed TCP-specific commands can be configured.
TCP Keepalive is enabled for all TCP-AO-enabled connections and cannot be disabled, even if disabled at the global level.
TCP-AO and TCP MD5 cannot be used in the same connection.
BGP and MSDP peer sessions must be cleared for the new TCP-AO configuration to take effect.
The send identifier configured at one end of the TCP peer connection must match the receive identifier at the other end of the connection.
Neither the send-id nor the recv-id can be reused for another key in the same keychain.
The no form of the keychain
keychain-name
tcp command removes the keychain.
The following example configures a TCP keychain and underlying options.
device# configure terminal device(config)# keychain mykey tcp device(config-keychain-tcp-mykey)# key-id 1 device(config-keychain-tcp-mykey-key-1)# password mykey device(config-keychain-tcp-mykey-key-1)# authentication-algorithm aes-128-cmac device(config-keychain-tcp-mykey-key-1)# send-id 1 device(config-keychain-tcp-mykey-key-1)# recv-id 1 device(config-keychain-tcp-mykey-key-1)# no accept-ao-mismatch device(config-keychain-tcp-mykey-key-1)# no include-tcp-options device(config-keychain-tcp-mykey-key-1)# send-lifetime start 06-01-2021 01:01:01 end 09-25-2021 06:59:00 device(config-keychain-tcp-mykey-key-1)# accept-lifetime start 05-01-2021 00:00:00 end 09-25-2021 00:00:00
| Release | Command History |
|---|---|
| 09.0.10 | This command was introduced. |