R211x-HP Flexfabric 11900 Security Command Reference

Table Of Contents
229
exchange-mode
Use exchange-mode to select an IKE negotiation mode for phase 1.
Use undo exchange-mode to restore the default.
Syntax
In non-FIPS mode:
exchange-mode { aggressive | main }
undo exchange-mode
In FIPS mode:
exchange-mode main
undo exchange-mode
Default
Main mode is used for phase 1.
Views
IKE profile view
Predefined user roles
network-admin
mdc-admin
Parameters
aggressive: Specifies the aggressive mode.
main: Specifies the main mode.
Usage guidelines
When a user at the local end of an IPsec tunnel obtains an IP address automatically and pre-shared key
authentication is used, HP recommends specifying the aggressive mode at the local end.
Examples
# Specify that IKE negotiation operates in main mode.
<Sysname> system-view
[Sysname] ike profile 1
[Sysname-ike-profile-1] exchange-mode main
Related commands
display ike proposal
ike dpd
Use ike dpd to enable sending DPD messages.
Use undo ike dpd to disable the DPD feature.
Syntax
ike dpd interval interval-seconds [ retry seconds ] { on-demand | periodic }