Installation Guide

Table Of Contents
IKEv2 Option Description
encryption-algorithm {aes-
gcm-256}
Configure the encryption algorithm to be supported.
NOTE
For the first release gcm-256 is supported.
transform {esp} Configure transform to be used.
For release 5.8.00 esp will be supported.
ESN-enable Enable Extended Sequence Number in this transform. By default it is disabled. Use this command to enable it.
NOTE
The setting for this command must match the setting for replay-protection (for the IPsec profile).
Configuring the IPsec Profile
The IPsec profile configuration defines the IPsec parameters to be used for encryption between IPsec routers.
For the IPSEC profile to be active and used for creating child-SA, the profile should be attached with a VTI interface. The profile should
have an IPsec proposal defined; otherwise, it will use the default IPsec proposal.
NOTE
There is no support for manual IPsec key entry.
If there is no IKE peer (source, destination, and VRF of VTI), then attaching the IPsec profile to VTI should initiate a new IKE session (if
the IKE profile is not configured as passive).
If there is already an IKE peer for the given source, destination, IKE profile and outgoing VRF, then a new child-SA should be created.
IKEv2 Option Description
ipsec Profile
<name>
Defines the IPsec parameters to be used between two IPsec routers, and enter IPsec configuration mode.
Description
<string>
(Optional) Description text for this IPsec profile.
Ike-profile
<ike-profile-name>
IKE profile attached with this IPsec profile.
Lifetime [minutes] (Optional) Lifetime of the IPsec SA in minutes. By default it is 8 hours, 480 minutes. The new security association
will be started 5 minutes before the old one is about to expire.
NOTE
Range of interval: 10 - 1440
Proposal
<proposal-name>
The IPsec proposal to be used with this IPsec profile. Multiple proposals can be specified.
Replay-protection (Optional) Disable anti-replay checking for a particular IPsec Profile. By default it is disabled.
NOTE
The setting of this command must match the setting of ESN-enable under the IPsec proposal.
IKEv2 Show Commands
IKEv2 show commands include configured proposals, policy, profile, security associations, sessions, certificates, counters, security
associations, statistics, proposals, and database for security policies.
IKEv2 Option Description
Show ikev2 proposal [name] Show configured IKEv2 proposals.
Show ikev2 policy [policy-name] Show IKEv2 policy.
Show ikev2 profile [profile-name] Show IKEv2 profile.
Product Overview
Brocade NetIron MLXe Series Hardware Installation Guide
52 53-1004203-03