Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

config

IKEv2

config

IPSec

Code Block
crypto ipsec security-association replay disable
crypto ipsec spi-prefix 8

Code Block
crypto ipsec transform-set AES-CBC-256-SHA-256
 esp-aes-256 esp-sha256-hmac
 mode transport
exit
crypto ipsec transform-set ESP-GCM-256
 esp-gcm-256
 mode        transport
exit

Code Block
crypto ipsec profile Ikev2IpsecProfile-1-internet
 set pfs group20
 set security-association lifetime kilobytes disable
 set security-association lifetime seconds 3600
 set ikev2-profile Ikev2Profile-1-internet
 set transform-set ESP-GCM-256 AES-CBC-256-SHA-256
 set spi-group 1
exit
crypto ipsec profile Ikev2IpsecProfile-1-mpls
 set pfs group20
 set security-association lifetime kilobytes disable
 set security-association lifetime seconds 3600
 set ikev2-profile Ikev2Profile-1-mpls
 set transform-set ESP-GCM-256 AES-CBC-256-SHA-256
 set spi-group 1
exit