R211x-HP Flexfabric 11900 Security Command Reference

Table Of Contents
226
Authentication-algorithm: SHA1
Encryption-algorithm: AES-CBC-128
Life duration(sec): 86400
Remaining key duration(sec): 86379
Exchange-mode: Main
Diffie-Hellman group: Group 1
NAT traversal: Not detected
Table 32 Command output
Field Description
Connection ID Identifier of the IKE SA.
Outside VPN
VPN instance name of the MPLS L3VPN to which the receiving interface
belongs.
Inside VPN
VPN instance name of the MPLS L3VPN to which the protected data
belongs.
Profile
Name of the matching IKE profile found in the IKE SA negotiation.
If no matching profile is found, this field is blank.
Transmitting entity Role of the IKE negotiation entity: Initiator or Responder.
Local IP IP address of the local gateway.
Local ID type Identifier type of the local gateway.
Local ID Identifier of the local gateway.
Remote IP IP address of the remote gateway.
Remote ID type Identifier type of the remote gateway.
Remote ID Identifier of the remote security gateway.
Authentication-method Authentication method used by the IKE proposal.
Authentication-algorithm
Authentication algorithm used by the IKE proposal:
MD5HMAC-MD5 algorithm.
SHA1HMAC-SHA1 algorithm.
Encryption-algorithm Encryption algorithm used by the IKE proposal.
Life duration(sec) Lifetime of the IKE SA in seconds.
Remaining key duration(sec) Remaining lifetime of the IKE SA in seconds.
Exchange-mode IKE negotiation mode in phase 1: main mode or aggressive mode.
Diffie-Hellman group DH group used for key negotiation in IKE phase 1.
NAT traversal Whether NAT traversal is detected.
dpd
Use dpd to enable the device to send DPD messages.
Use undo dpd to disable the IKE DPD function.