< Home

ike sm-encryption-key-length enable

Function

The ike sm-encryption-key-length enable command enables IKE negotiation packets to carry the SM encryption key length.

The undo ike sm-encryption-key-length enable command disables IKE negotiation packets from carrying the SM encryption key length.

By default, IKE negotiation packets do not carry the SM encryption key length.

Format

ike sm-encryption-key-length enable

undo ike sm-encryption-key-length enable

Parameters

None

Views

System view

Default Level

2: Configuration level

Usage Guidelines

When a digital envelop is used for IKE negotiation, the negotiation fails if packets sent by the initiator carry the SM encryption key length but the responder cannot process the SM encryption key length. To solve this problem, run the undo ike sm-encryption-key-length enable command on the IKE initiator to disable IKE negotiation packets from carrying the SM encryption key length.

Example

# Enable IKE negotiation packets to carry the SM encryption key length.

<sysname> system-view
[sysname] ike sm-encryption-key-length enable
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >