Cisco MDS 9000 Series Configuration Manual page 285

Security
Hide thumbs Also See for MDS 9000 Series:
Table of Contents

Advertisement

Configuring Cisco TrustSec Fibre Channel Link Encryption
switch. The ingress SA specifies which keys or parameters are to be used to decrypt the packets entering that
particular port.
Note
While configuring ESP, only E and Auto port modes are supported.
This section covers the following topics:
Configuring ESP on Ingress Port
To configure SA to the ingress hardware, follow these steps:
Procedure
Step 1
switch# configure terminal
Enters the configuration mode.
Step 2
switch(config)# interface fc x/y
Configures the FC interface on slot x, port y.
Note
Step 3
switch(config-if)# fcsp esp manual
Enters the ESP configuration submode.
Step 4
switch(config-if-esp)# ingress-sa spi_number
Configures the SA to the ingress hardware.
Step 5
switch (config-if-esp)# no ingress-sa spi_number
(Optional) Removes the SA from the ingress hardware.
Configuring ESP on Egress Ports
To configure SA to the egress hardware, follow these steps:
Procedure
Step 1
switch# configure terminal
Enters the configuration mode.
Step 2
switch(config)# interface fc x/y
Configures the FC interface on slot x, port y.
Note
7
If SA is not configured in the ingress port, then running this command returns an error message.
Selecting a portchannel will apply the configuration on all members of the portchannel.
Selecting a portchannel will apply the configuration on all members of the portchannel.
7
Cisco MDS 9000 Series Security Configuration Guide, Release 8.x
Configuring ESP on Ingress Port
267

Advertisement

Table of Contents
loading

Table of Contents