Motorola Wing 5 Manual
Have a look at the manual Motorola Wing 5 Manual online for free. It’s possible to download the document as PDF or print. UserManuals.tech offer 249 Motorola manuals and user’s guides for free. Share the user manual or guide on Facebook, Twitter or Google+.
PROFILES 7 - 45 7.1.14.2 encryption isakmp-policy Configures the encryption level transmitted using the crypto isakmp command Supported in the following platforms: AP300 AP621 AP650 AP6511 AP6521 AP6532 AP71XX RFS4000 RFS6000 RFS7000 NX9000 NX9500 Syntax encryption [3des|aes|aes-192|aes-256|des] Parameters • encryption [3des|aes|aes-192|aes-256|des] Examples rfs7000-37FABE(config-isakmp-policy-test)#encryption 3des rfs7000-37FABE(config-isakmp-policy-test)# rfs7000-37FABE(config-profile-default-rfs7000-isakmp-policy-test)#show context crypto isakmp policy test authentication rsa-sig encryption 3des rfs7000-37FABE(config-profile-default-rfs7000-isakmp-policy-test)# Related Commands encryption Sets an encryption algorithm for the ISAKMP protection suite 3des Configures triple data encryption standard aes-192 Configures Advanced Encryption Standard (AES) (128 bit keys) aes-256 Configures AES (256 bit keys) des Configures Data Encryption Standard (DES) (56 bit keys) noDisables or reverts ISAKMP policy settings to their default
7 - 46 WiNG CLI Reference Guide 7.1.14.3 group isakmp-policy Specifies the Diffie-Hellman (DH) group (1 or 2) used by the IKE policy to generate keys (used to create IPSec SA). Specifying the group enables you to declare the size of the modulus used in DH calculation. Supported in the following platforms: AP300 AP621 AP650 AP6511 AP6521 AP6532 AP71XX RFS4000 RFS6000 RFS7000 NX9000 NX9500 Syntax group [1|2|5] Parameters • group [1|2|5] Usage Guidelines The local IKE policy and the peer IKE policy must have matching group settings for negotiation to be successful. Examples rfs7000-37FABE(config-profile-default-RFS7000-isakmp-policy-test)#group 1 rfs7000-37FABE(config-profile-default-RFS7000-isakmp-policy-test)#show context crypto isakmp policy test authentication rsa-sig encryption 3des group 1 rfs7000-37FABE(config-profile-default-RFS7000-isakmp-policy-test)# Related Commands [1|2|5] Select one of the following DH groups: 1– Configures DH group 1 2 – Configures DH group 2 5 – Configures DH group 5 noDisables or reverts ISAKMP policy settings to their default
PROFILES 7 - 47 7.1.14.4 hash isakmp-policy Specifies the hash algorithm used to authenticate data transmitted over the IKE SA Supported in the following platforms: AP300 AP621 AP650 AP6511 AP6521 AP6532 AP71XX RFS4000 RFS6000 RFS7000 NX9000 NX9500 Syntax hash [md5|sha] Parameters • hash [md5|sha] Examples rfs7000-37FABE(config-profile-default-RFS7000-isakmp-policy-test)#hash md5 rfs7000-37FABE(config-profile-default-RFS7000-isakmp-policy-test)#show context crypto isakmp policy test authentication rsa-sig encryption 3des group 1 hash md5 rfs7000-37FABE(config-profile-default-RFS7000-isakmp-policy-test)# Related Commands md5 Uses Message Digest 5 (MD5) hash algorithm sha Uses Secure Hash Authentication (SHA) hash algorithm noDisables or reverts ISAKMP policy settings to their default
7 - 48 WiNG CLI Reference Guide 7.1.14.5 lifetime isakmp-policy Specifies how long an IKE SA is valid before it expires Supported in the following platforms: AP300 AP621 AP650 AP6511 AP6521 AP6532 AP71XX RFS4000 RFS6000 RFS7000 NX9000 NX9500 Syntax lifetime Parameters • lifetime Examples rfs7000-37FABE(config-isakmp-policy-test)#lifetime 40000 rfs7000-37FABE(config-profile-default-RFS7000-isakmp-policy-test)#show context crypto isakmp policy test authentication rsa-sig encryption 3des group 1 hash md5 lifetime 40000 rfs7000-37FABE(config-profile-default-RFS7000-isakmp-policy-test)# Related Commands lifetime Specifies how many seconds an IKE SA lasts before it expires. Set a time stamp from 60 - 2147483646 seconds. – Specify a value from 60 - 2147483646 seconds. noDisables or reverts ISAKMP policy settings to their default
PROFILES 7 - 49 7.1.14.6 no isakmp-policy Negates a command or reverts settings to their default. The no command, when used in the ISAKMP policy mode, defaults the ISAKMP protection suite settings. Supported in the following platforms: AP300 AP621 AP650 AP6511 AP6521 AP6532 AP71XX RFS4000 RFS6000 RFS7000 NX9000 NX9500 Syntax no [authentication|encryption|group|hash|lifetime] Parameters • no [authentication|encryption|group|hash|lifetime] Examples rfs7000-37FABE(config-isakmp-policy-test)#no authentication rfs7000-37FABE(config-isakmp-policy-test)#no lifetime rfs7000-37FABE(config-isakmp-policy-test)# Related Commands no authentication Reverts to the default authentication method no encryption Reverts to the default encryption algorithm for protection suites no group Reverts to the default DH group 2 no hash Reverts to the default hash algorithm for the protection suites no lifetime Reverts to the default lifetime settings for the ISAKMP SA authenticationAuthenticates RSA pre-share keys encryptionConfigures encryption level of the data transmitted using the crypto-isakmp command groupSpecifies Diffie-Hellman group (1 or 2) used by the IKE policy hashSpecifies hash algorithm lifetimeSpecifies how long an IKE SA is valid before it expires
7 - 50 WiNG CLI Reference Guide noNegates a commnd or sets its default clrscrClears the display screen commitCommits (saves) changes made in the current session doRuns commands from EXEC mode endEnds and exits the current mode and moves to the PRIV EXEC mode exitEnds the current mode and moves to the previous mode helpDisplays the interactive help system revertReverts changes to their last saved configuration serviceInvokes service commands to troubleshoot or debug (config-if) instance configurations showDisplays running system information writeWrites information to memory or terminal
PROFILES 7 - 51 7.1.15 crypto-group Creating Profiles Use the (config) instance to configure crypto group configuration commands: rfs7000-37FABE(config-profile-default-RFS7000)#crypto isakmp client configuration group default rfs7000-37FABE(config-profile-default-RFS7000-crypto-group)# rfs7000-37FABE(config-profile-default-RFS7000-crypto-group)#? Crypto Client Config commands: dns Domain Name Server wins Windows name server clrscr Clears the display screen commit Commit all changes made in this session end End current mode and change to EXEC mode exit End current mode and down to previous mode help Description of the interactive help system revert Revert changes service Service Commands show Show running system information write Write running configuration to memory or terminal rfs7000-37FABE(config-profile-default-RFS7000-crypto-group) Table 7.4 summarizes crypto group commands Table 7.4Crypto Group Commands Command Description Reference dnsConfigures domain name server settingspage 7-52 wnsConfigures Windows name server settingspage 7-53 clrscrClears the display screenpage 5-3 commitCommits (saves) changes made in the current sessionpage 5-4 doRuns commands from EXEC modepage 4-66 endEnds and exits the current mode and moves to the PRIV EXEC modepage 5-5 exitEnds the current mode and moves to the previous modepage 5-6 helpDisplays the interactive help systempage 5-7 revertReverts changes to their last saved configurationpage 5-13 serviceInvokes service commands to troubleshoot or debug (config-if) instance configurationspage 5-14 showDisplays running system informationpage 6-4 writeWrites information to memory or terminalpage 5-42
7 - 52 WiNG CLI Reference Guide 7.1.15.1 dns crypto-group Configures the DNS server Supported in the following platforms: AP300 AP621 AP650 AP6511 AP6521 AP6532 AP71XX RFS4000 RFS6000 RFS7000 NX9000 NX9500 Syntax dns Parameters • dns Examples rfs7000-37FABE(config-profile-default-RFS7000-crypto-group)#dns 171.16.10.6 rfs7000-37FABE(config-profile-default-RFS7000-crypto-group)#show context crypto isakmp client configuration group default dns 172.16.10.6 rfs7000-37FABE(config-profile-default-RFS7000-crypto-group)# Sets the IP address for the DNS server
PROFILES 7 - 53 7.1.15.2 wns crypto-group Configures the Windows name server Supported in the following platforms: AP300 AP621 AP650 AP6511 AP6521 AP6532 AP71XX RFS4000 RFS6000 RFS7000 NX9000 NX9500 Syntax wins Parameters • wins Examples rfs7000-37FABE(config-profile-default-rfs7000-crypto-group)#wns 172.16.10.8 rfs7000-37FABE(config-profile-default-RFS7000-crypto-group)#wins 172.16.10.8 rfs7000-37FABE(config-profile-default-RFS7000-crypto-group)#show context crypto isakmp client configuration group default wins 172.16.10.8 dns 172.16.10.6 rfs7000-37FABE(config-profile-default-RFS7000-crypto-group)# Sets the IP address for the Windows name server
7 - 54 WiNG CLI Reference Guide 7.1.16 dscp-mapping Creating Profiles Configures IP Differentiated Services Code Point (DSCP) to 802.1p priority mapping for untagged frames Supported in the following platforms: AP300 AP621 AP650 AP6511 AP6521 AP6532 AP71XX RFS4000 RFS6000 RFS7000 NX9000 NX9500 Syntax dscp-mapping priority Parameters • dscp-mapping priority Examples rfs7000-37FABE(config-profile-default-RFS7000)#dscp-mapping 20 priority 7 rfs7000-37FABE(config-profile-default-RFS7000)#show context profile RFS7000 default-RFS7000 dscp-mapping 20 priority 7 no autoinstall configuration no autoinstall firmware crypto isakmp policy default crypto ipsec transform-set default esp-aes-256 esp-sha-hmac interface me1 interface ge1 ip dhcp trust qos trust dscp Related Commands Specify a DSCP value of a received IP packet. This could be a single value or a list. For example, 10-20,25,30-35 priority Specifies the 802.1p priority to use for a packet if untagged. The priority is set on a scale of 0 - 7 noDisables or reverts settings to their default