Cisco Cisco ASR 5000

Page of 9109
Crypto Map IPSec IKEv1 Configuration Mode Commands   
▀  set 
 
 
▄  Command Line Interface Reference, StarOS Release 18 
2994 
   
set 
Configures parameters for the dynamic crypto map. 
Product
 
ePDG 
FA 
GGSN 
HA 
HeNBGW 
HNBGW 
HSGW 
MME 
P-GW 
PDSN 
S-GW 
SAEGW 
SCM 
SecGW 
SGSN 
Privilege
 
Security Administrator 
Mode
 
Exec > Global Configuration > Context Configuration > Crypto Map IPSec IKEv1 Configuration 
configure > context context_name > crypto map policy_name ipsec-ikev1
 
Entering the above command sequence results in the following prompt: 
[context_name]host_name(config-crypto-map)# 
Syntax
 
set { bgp
 
peer_address
 
 | control-dont-fragment { clear-bit | copy-bit | set-bit } 
| ikev1 natt [ keepalive
 
sec
 
] | ip mtu
 
bytes
 
| ipv6 mtu
 
bytes
 
| mode { aggressive | 
main }
 
| peer
 
peer_address
 
| pfs { group1 | group2 | group5 } |
 
phase1-idtype { id-
key-id | ipv4-address [ mode { aggressive | main } ] |
 
phase2-idtype { ipv4-
address | ipv4-address-subnet } | security-association lifetime { disable-phase2-
rekey | keepalive | kilo-bytes
 
kbytes
 
| seconds
 
secs
 
}
 
transform-set
 
transform_name
 
transform-set
 
transform_name2 ...
 
transform-set
 
transform_name6
 
]
 
no set { ikev1 natt | pfs | phase1-idtype | 
 
phase2-idtype | security-association 
lifetime { disable-phase2-rekey | keepalive | kilo-bytes | seconds } | transform-
set 
transform_name
 
[ transform-set
 
transform_name2 ...
 
transform-set
 
transform_name6
 
]