
Configuring IPsec
304111-A Rev 00
3-5
The kset npk command stores your NPK_value in the router NVRAM, and it
calculates a hash of this value that it stores in the router MIB.
5.
Enter the save config <config_file_name> command. You cannot exit the
secure shell without saving the configuration. This is necessary so that upon
rebooting the router with the saved configuration file, the hash of the NPK in
the MIB corresponds with the NPK in NVRAM.
6.
Enter kexit to exit the secure shell.
Changing NPKs
To maintain security, periodically change the NPKs entered into the routers.
To change an NPK, enter the
kset NPK command, using the steps you used to
create the original NPK (see “Entering an NPK and a Seed for Encryption” on
page 3-4).
The new NPK overwrites the original, and IPsec uses the new NPK value.
To change the NPK value used by the MIB:
1.
At the Technician Interface prompt, enter ksession.
This command allows you to enter the secure shell. You are prompted for your
password.
2.
Enter your password.
The prompt changes to:
SSHELL.
3.
Enter ktranslate
<old_NPK_value>
.
The MIB now has the same NPK as the router.
4.
Save the configuration file.
Commentaires sur ces manuels