About The Autopeer Option - HP Cisco MDS 9020 - Fabric Switch Configuration Manual

Cisco mds 9000 family cli configuration guide, release 3.x (ol-16184-01, april 2008)
Hide thumbs Also See for Cisco MDS 9020 - Fabric Switch:
Table of Contents

Advertisement

Crypto IPv4-ACLs
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
Command
Step 4
switch(config-crypto-map-ip)# set
security-association lifetime kilobytes
2560
switch(config-crypto-map-ip)# set
security-association lifetime gigabytes
4000
switch(config-crypto-map-ip)# set
security-association lifetime megabytes
5000
switch(config-crypto-map-ip)# no set
security-association lifetime megabytes

About the AutoPeer Option

Setting the peer address as auto-peer in the crypto map indicates that the destination endpoint of the
traffic should be used as the peer address for the SA. Using the same crypto map, a unique SA can be set
up at each of the endpoints in the subnet specified by the crypto map's IPv4-ACL entry. Auto-peer
simplifies configuration when traffic endpoints are IPsec capable. It is particularly useful for iSCSI,
where the iSCSI hosts in the same subnet do not require separate configuration.
Figure 35-7
option, only one crypto map entry is needed for all the hosts from subnet X to set up SAs with the switch.
Each host will set up its own SA, but will share the crypto map entry. Without the auto-peer option, each
host needs one crypto map entry.
See the
Cisco MDS 9000 Family CLI Configuration Guide
35-26
shows a scenario where the auto-peer option can simplify configuration. Using the auto-peer
"Sample iSCSI Configuration" section on page 35-39
Chapter 35
Configuring IPsec Network Security
Purpose
Configures the traffic-volume lifetime for this SA in
kilobytes. The lifetime ranges from 2560 to
2147483647 kilobytes.
Configures the traffic-volume lifetime for this SA to
time out after the specified amount of traffic (in
gigabytes) have passed through the FCIP link using
the SA. The lifetime ranges from 1 to 4095 gigabytes.
Configures the traffic-volume lifetime for this SA in
megabytes. The lifetime ranges from 3 to 4193280
megabytes.
Reverts to the global settings.
for more details.
OL-16184-01, Cisco MDS SAN-OS Release 3.x

Advertisement

Table of Contents
loading

Table of Contents