encryption-algorithm (Security IKE)
Statement introduced in Junos OS Release 8.5. Support for aes-128-gcm and aes-256-gcm options added in Junos OS Release 15.1X49-D40.
Starting in Junos OS Release 20.2R1, we’ve changed the help text description as NOT RECOMMENDED for the CLI options 3des-cbc and des-cbc.
Configure an encryption algorithm for an IKE proposal. The device does not delete existing IPsec SAs when you update the encryption-algorithm configuration in the IKE proposal.
When aes-128-gcm or aes-256-gcm encryption algorithms are configured in the IPsec proposal, it is not mandatory to configure AES-GCM encryption algorithm in the corresponding IKE proposal.
Required Privilege Level
security—To view this statement in the configuration.
security-control—To add this statement to the configuration.