Enterasys Networks XSR CLI Router User Manual


 
Remote Peer Show Commands
XSR CLI Reference Guide 14-105
show crypto isakmp proposal
ThiscommandlistsattributesforeachInternetKeyExchange(IKE)proposal.ISAKMPproposals
createdwithEZIPSecaremarkedwithanasterisk(*)inthe
showoutput.Theseproposalsmaynot
beusedinotheruserdefinedISAKMPpolicies‐theyarereservedforEZIPSec.
Syntax
show crypto isakmp proposal
Mode
EXECorGlobalconfiguration:XSR> or XSR(config)#
Sample Output
XSR#show crypto isakmp proposal
Name Authentication Encrypt Integrity Group Lifetime
test PreSharedKeys AES HMAC-MD5 Modp1024
ThefollowingoutputwasproducedbyISAKMP proposalscreatedviaEZIPSec:
XSR#show crypto isakmp proposal
Name Authentication Encrypt Integrity Group Lifetime
*ez-ike-3des-sha-psk PreSharedKeys 3DES HMAC-SHA Modp1024 28800
*ez-ike-3des-md5-psk PreSharedKeys 3DES HMAC-MD5 Modp1024 28800
*ez-ike-3des-sha-rsa RSASignature 3DES HMAC-SHA Modp1024 28800
*ez-ike-3des-md5-rsa RSASignature 3DES HMAC-MD5 Modp1024 28800
show crypto isakmp sa
ThiscommandlistsallcurrentInternetKeyExchangeSecurityAssociations(SAs)foryourXSR.
AnSAoccupiesacertainstatedependinguponwhereintheauthenticationprocessthepeersare
andwhatexchangemodetheyshare‐Aggressive,MainorQuick.Duringlongexchanges,someof
theMMstatesmaybe
seen.RefertotheParameterDescriptionsforfurtherexplanation.
Syntax
show crypto isakmp sa
Mode
EXECorGlobalconfiguration:XSR> or XSR(config)#
Sample Output
ThefollowingoutputdisplaystwoSAs,oneinMainModeexchangepreparingtoauthenticate
andtheotherinQuickModeexchangereadyfortraffic:
XSR#show crypto isakmp sa
Connection-ID State Source Destination Lifetime
526 MM_KEY_AUTH 192.168.2.2 192.168.2.1
9 QM_IDLE 192.168.55.10 141.154.196.87