keychain tcp

Configures a keychain module specific to TCP.
Syntax
keychain keychain-name tcp
no keychain keychain-name tcp
Command Default

No keychain is configured by default.

Parameters
keychain-name
Specifies the name of the keychain.
tcp
Specifies that the keychain can be applied only to TCP connections.

TCP Authentication Options (AO):

[no] accept-ao-mismatch
Determines whether the ICX device accepts or denies TCP segments with a mismatch in TCP-AO support between the TCP peers. By default, mismatched segments are accepted. When the option is disabled, TCP-AO packets with a mismatch are discarded.
[no] authentication-algorithm aes-128-cmac
Configures the aes-128-cmac algorithm for TCP authentication. The algorithm hmac-sha-1 is also supported.
[no] include-tcp-options
Determines whether all TCP options are included in the Message Authentication Code (MAC) calculation. By default, all TCP options are included. When the no form of the command is configured, only the TCP-AO option is included in the MAC calculation.
[no] recv-id id
Configures the identifier to be compared with the key identifier received in a TCP segment. Valid values are 0 through 255. The no form of the command removes the identifier.
[no] send-id id
Configures the identifier sent in an outgoing TCP segment. Valid values are 0 through 255. The no form of the command removes the identifier.
Modes

Global configuration mode

Usage Guidelines

The keychain keychain-name tcp command is not supported for ICX 7150 devices.

A maximum of 64 keychains can be configured, including TCP keychains and other types.

The keychain keychain-name tcp command takes the configuration to the TCP keychain configuration mode, in which the listed TCP-specific commands can be configured.

TCP Keepalive is enabled for all TCP-AO-enabled connections and cannot be disabled, even if disabled at the global level.

TCP-AO and TCP MD5 cannot be used in the same connection.

BGP and MSDP peer sessions must be cleared for the new TCP-AO configuration to take effect.

The send identifier configured at one end of the TCP peer connection must match the receive identifier at the other end of the connection.

Neither the send-id nor the recv-id can be reused for another key in the same keychain.

The no form of the keychain keychain-name tcp command removes the keychain.

Examples

The following example configures a TCP keychain and underlying options.

device# configure terminal
device(config)# keychain mykey tcp
device(config-keychain-tcp-mykey)# key-id 1
device(config-keychain-tcp-mykey-key-1)# password mykey
device(config-keychain-tcp-mykey-key-1)# authentication-algorithm aes-128-cmac
device(config-keychain-tcp-mykey-key-1)# send-id 1
device(config-keychain-tcp-mykey-key-1)# recv-id 1
device(config-keychain-tcp-mykey-key-1)# no accept-ao-mismatch
device(config-keychain-tcp-mykey-key-1)# no include-tcp-options
device(config-keychain-tcp-mykey-key-1)# send-lifetime start 06-01-2021 01:01:01 end 09-25-2021 06:59:00
device(config-keychain-tcp-mykey-key-1)# accept-lifetime start 05-01-2021 00:00:00 end 09-25-2021 00:00:00
History
Release Command History
09.0.10 This command was introduced.