Security and authentication
9.3 IPsec VPN
SCALANCE S615 Command Line Interface
394 Configuration Manual, 06/2015, C79000-G8976-C406-02
You display this setting and other information with the show ipsec conn-phase1 command.
You disable the use of the default list with the
no default-ciphers command.
ike-keyderivation
Description
With this command, you configure the required Diffie-Hellmann group (DH) from which a key
will be generated.
● The default list is not used.
● You are in the IPSEC PHASE configuration mode.
The command prompt is as follows:
cli(config-conn-phs1)#
Call up the command with the following parameters:
ike-keyderivation {dhgroup <1|2|5|14|15|16|17|18>}
The parameters have the following meaning:
Diffie-Hellmann group (DH) Specify the required Diffie-Hellmann
group (DH).
• 1
•
2
•
5
•
14
•
15
•
16
•
17
•
The Diffie-Hellmann group (DH) is configured.