R211x-HP Flexfabric 11900 Security Command Reference

Table Of Contents
324
Crypto engine commands
crypto-engine accelerator disable
Use crypto-engine accelerator disable to disable hardware crypto engines.
Use undo crypto-engine accelerator disable to enable hardware crypto engines.
Syntax
crypto-engine accelerator disable
undo crypto-engine accelerator disable
Default
Hardware crypto engines are enabled.
Views
System view
Predefined user roles
network-admin
mdc-admin
Usage guidelines
Crypto engines include hardware crypto engines and software crypto engines.
By default, hardware crypto engines are enabled. You can use the crypto-engine accelerator disable
command to disable them globally. However, disabling hardware crypto engines can degrade the
encryption or decryption performance. HP recommends you not disable hardware crypto engines except
for testing, debugging, or troubleshooting purposes.
Enabling or disabling hardware crypto engines affects different service modules differently.
For example, for IPsec services, enabling or disabling hardware crypto engines affects only newly
established IPsec SAs. The existing IPsec SAs still use the previously selected crypto engine for data
encryption. HP recommends using the reset ipsec sa command to delete all existing IPsec SAs before you
enable or disable hardware crypto engines.
Examples
# Disable hardware crypto engines.
<Sysname> system-view
[Sysname] crypto-engine accelerator disable
display crypto-engine
Use display crypto-engine to display information about crypto engines, including crypto engine names
and supported algorithms.
Syntax
display crypto-engine