580
1 RSA-SIG SHA1 DES-CBC Group 1 5000
11 PRE-SHARED-KEY SHA1 DES-CBC Group 1 50000
default PRE-SHARED-KEY SHA1 DES-CBC Group 1 86400
Table 85 Command output
Priority Priority of the IKE proposal
Authentication method Authentication method used by the IKE proposal.
Authentication algorithm
Authentication algorithm used in the IKE proposal:
• MD5—HMAC-MD5 algorithm.
• SHA1—HMAC-SHA1 algorithm.
• SHA256—HMAC-SHA256 algorithm.
• SHA384—HMAC-SHA384 algorithm.
• SHA512—HMAC-SHA512 algorithm.
• SM3—HMAC-SM3 algorithm.
Encryption algorithm
Encryption algorithm used by the IKE proposal:
• 3DES-CBC—168-bit 3DES algorithm in CBC mode.
• AES-CBC-128—128-bit AES algorithm in CBC mode.
• AES-CBC-192—192-bit AES algorithm in CBC mode.
• AES-CBC-256—256-bit AES algorithm in CBC mode.
• DES-CBC—56-bit DES algorithm in CBC mode.
• SM1-CBC-128—128-bit SM1 algorithm in CBC mode.
• SM1-CBC-192—192-bit SM1 algorithm in CBC mode.
• SM1-CBC-256—256-bit SM1 algorithm in CBC mode.
Diffie-Hellman group DH group used in IKE negotiation phase 1.
Duration (seconds) IKE SA lifetime (in seconds) of the IKE proposal
Related commands
ike proposal
display ike sa
Use display ike sa to display information about IKE SAs.
Syntax
display ike sa [ verbose [ connection-id connection-id | remote-address [ ipv6 ] remote-address
[ vpn-instance vpn-instance-name ] ] ]
Views
Any view
Predefined user roles
network-admin
network-operator
Parameters
verbose: Displays detailed information.
connection-id connection-id: Displays detailed information about IKE SAs by connection ID in the
range of 1 to 2000000000.