Cisco MDS 9000 Series Configuration Manual page 220

Security
Hide thumbs Also See for MDS 9000 Series:
Table of Contents

Advertisement

Displaying IPsec Configurations
#
1:
#
3:
#
63:
entry
Displays SPD Information for a Specific Interface
switch# show crypto spd domain ipsec interface gigabitethernet 4/2
Policy Database for interface: GigabitEthernet3/1, direction: Both
#
0:
#
1:
#
2:
# 127:
Displays Detailed iSCSI Session Information for a Specific Interface
switch# show iscsi session detail
Initiator iqn.1987-05.com.cisco:01.9f39f09c7468 (ips-host16.cisco.com)
Initiator ip addr (s): 10.10.10.5
Session #1 (index 24)
Discovery session, ISID 00023d000001, Status active
Session #2 (index 25)
Target ibm1
VSAN 1, ISID 00023d000001, TSIH 0, Status active, no reservation
Type Normal, ExpCmdSN 42, MaxCmdSN 57, Barrier 0
MaxBurstSize 0, MaxConn 1, DataPDUInOrder Yes
DataSeqInOrder Yes, InitialR2T Yes, ImmediateData No
Registered LUN 0, Mapped LUN 0
Stats:
PDU: Command: 41, Response: 41
Bytes: TX: 21388, RX: 0
Number of connection: 1
Connection #1
iSCSI session is protected by IPSec -----------The iSCSI session protection status
Local IP address: 10.10.10.4, Peer IP address: 10.10.10.5
CID 0, State: Full-Feature
StatSN 43, ExpStatSN 0
MaxRecvDSLength 131072, our_MaxRecvDSLength 262144
CSG 3, NSG 3, min_pdu_size 48 (w/ data 48)
AuthMethod none, HeaderDigest None (len 0), DataDigest None (len 0)
Version Min: 0, Max: 0
FC target: Up, Reorder PDU: No, Marker send: No (int 0)
Received MaxRecvDSLen key: Yes
Displays FCIP Information for a Specific Interface
switch# show interface fcip 1
fcip1 is trunking
Hardware is GigabitEthernet
Port WWN is 20:50:00:0d:ec:08:6c:c0
Peer port WWN is 20:10:00:05:30:00:a7:9e
Admin port mode is auto, trunk mode is on
Port mode is TE
Port vsan is 1
Speed is 1 Gbps
Trunk vsans (admin allowed and active) (1)
Trunk vsans (up)
Trunk vsans (isolated)
Trunk vsans (initializing)
Using Profile id 1
Peer Information
Cisco MDS 9000 Series Security Configuration Guide, Release 8.x
202
deny
udp any any port eq 500 <---------------------- UDP default entry
permit ip 10.10.100.0 255.255.255.0 10.10.100.0 255.255.255.0
deny
ip any any <---------------------------------------- Clear text default
deny
udp any port eq 500 any
deny
udp any any port eq 500
permit ip 10.10.10.0 255.255.255.0 10.10.10.0 255.255.255.0
deny
ip any any
(interface GigabitEthernet2/1)
Configuring IPSec Network Security
(1)
()
()

Advertisement

Table of Contents
loading

Table of Contents