Using the tcp-kind command, you can specify the option type to be used while sending packets with TCP Enhanced Authentication option.
Using the undo tcp-kind command, you can restore the TCP kind value to default.
By default, it is 254.
Usage Scenario
A keychain ensures a secure protocol packet transmission by changing the authentication algorithm and key dynamically. Packets to be transmitted over non-TCP and TCP connections are authenticated using the authentication and encryption algorithms corresponding to a key ID. The difference lies in that the TCP connection needs to be authenticated to enhance the security.
TCP connection request packets carry enhanced authentication options and are authenticated by a specified authentication algorithm. At present, different vendors use different kind values to specify the enhanced authentication option. Kind values configured for two communication devices must be identical.Prerequisites
Two communication devices with the keychain authentication mode establish a TCP connection.
Follow-up Procedure
If TCP connection request packets carry enhanced authentication options, the kind value must be specified in the packets.
Precautions
After setting the same kind value for the two communication devices, specify the same algorithm ID corresponding to the authentication algorithm for the two devices.