TMS zl Management and Configuration Guide ST.1.2.100916
A-143
Command-Line Reference
IPsec Policy Context
Figure A-12. IPsec Auto Keys Context
To enter the IPsec auto keys context, enter the following command from the
IPsec policy apply context:
Syntax: key-exchange-method auto
To verify your location in the CLI, check the prompt. In the Manual Key
Exchange context, the prompt is hostswitch(tms-module-<slot
ID>:ipsec:apply:auto)#.
To exit the IPsec auto keys context, enter the following:
Syntax: exit
If you have not set all of the necessary configurations, you will be prompted
to do so and asked whether you actually want to exit.
From the IPsec auto keys context, you can:
■ Set the IKEv1 policy (page A-144)
■ Enable (or disable) PFS (Perfect Forward Secrecy) for keys (page A-144)
■ Set the SA lifetime values (page A-144)