Cisco MDS 9000 Series Configuration Manual page 286

Security
Hide thumbs Also See for MDS 9000 Series:
Table of Contents

Advertisement

Configuring ESP Modes
Step 3
switch(config-if)# fcsp esp manual
Enters the ESP configuration submode.
Step 4
switch(config-if-esp)# egress-sa spi_number
Configures the SA to the egress hardware.
Step 5
switch(config-if)# no fcsp esp manual
(Optional) Removes the SA from the ingress and egress hardware.
Example
Note
To apply the SA to the ingress and egress hardware of an interface, the interface needs to be in the
admin shut mode.
Configuring ESP Modes
Configure the ESP settings for the ports as GCM to enable message authentication and encryption or as GMAC
to enable message authentication.
The default ESP mode is AES-GCM.
This section covers the following topics:
Configuring AES-GCM
To configure the AES-GCM mode, follow these steps:
Procedure
Step 1
switch# configure terminal
Enters the configuration mode.
Step 2
switch(config)# interface fc x/y
Configures the FC interface on slot x, port y.
Note
Step 3
switch(config-if)# fcsp esp manual
Enters the ESP configuration submode to configure the ESP settings on each port.
Step 4
switch(config-if-esp)# mode gcm
8
If SA is not configured in the egress port, then running this command returns an error message.
Cisco MDS 9000 Series Security Configuration Guide, Release 8.x
268
Selecting a portchannel would apply the configuration on all members of the portchannel.
Configuring Cisco TrustSec Fibre Channel Link Encryption
8

Advertisement

Table of Contents
loading

Table of Contents