prf

Configures a pseudorandom function (PRF) for an Internet Key Exchange version 2 (IKEv2) proposal.
Syntax
prf { sha256 | sha384 }
no prf { sha256 | sha384 }
Command Default

The default algorithm is SHA-384.

Parameters
sha256
Specifies SHA-2 family 256-bit (HMAC variant) as the hash algorithm.
sha384
Specifies SHA-2 family 384-bit (HMAC variant) as the hash algorithm.
Modes

IKEv2 proposal configuration mode

Usage Guidelines

This hash algorithm is used to generate key material during IKEv2 SA negotiations.

Both algorithms may be configured for an IKEv2 proposal.

When only one PRF algorithm is configured for an IKEv2 proposal, removing it restores the default configuration.

The no form of the command removes the specified PRF algorithm configuration.

Examples

The following example shows how to configure SHA-256 as the hash algorithm for an IKEv2 proposal named ikev2_prop.

device(config)# ikev2 proposal ikev2_prop
device(config-ikev2-proposal-ikev2_prop)# prf sha256
History
Release version Command history
08.0.50 This command was introduced.