Verifying Ipsec Configuration Compatibility Using The Cli - Cisco 9134 - MDS Multilayer Fabric Switch Troubleshooting Manual

Mds 9000 family
Hide thumbs Also See for 9134 - MDS Multilayer Fabric Switch:
Table of Contents

Advertisement

Chapter 22
Troubleshooting IPsec
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m

Verifying IPsec Configuration Compatibility Using the CLI

To verify the compatibility of the IPsec configurations of MDS A and MDS C shown in
using the CLI, follow these steps:
Use the show crypto map domain ipsec command and the show crypto transform-set domain ipsec
Step 1
command. The following command outputs display the fields discussed in
MDSA# show crypto map domain ipsec
Crypto Map "cmap-01" 1 ipsec
Interface using crypto map set cmap-01:
MDSC# show crypto map domain ipsec
Crypto Map "cmap-01" 1 ipsec
Interface using crypto map set cmap-01:
MDSA# show crypto transform-set domain ipsec
Transform set:tfs-01 {esp-3des null}
Transform set:tfs-02 {esp-3des esp-md5-hmac}
Transform set:ipsec_default_transform_set {esp-aes 128 esp-sha1-hmac}
MDSC# show crypto transform-set domain ipsec
Transform set:tfs-01 {esp-3des null}
Transform set:tfs-02 {esp-3des esp-md5-hmac}
Transform set:ipsec_default_transform_set {esp-aes 128 esp-sha1-hmac}
Step 2
Ensure that the ACLs are compatible in the show crypto map domain ipsec command outputs for both
switches.
Ensure that the peer configuration is correct in the show crypto map domain ipsec command outputs
Step 3
for both switches.
Ensure that the transform sets are compatible in the show crypto transform-set domain ipsec command
Step 4
outputs for both switches.
Ensure that the PFS settings in the show crypto map domain ipsec command outputs are configured
Step 5
the same on both switches.
OL-9285-05
Peer = 10.10.100.232
IP ACL = acl1
permit ip 10.10.100.231 255.255.255.255 10.10.100.232 255.255.255.255
Transform-sets: tfs-02,
Security Association Lifetime: 3000 gigabytes/120 seconds
PFS (Y/N): Y
PFS Group: group5
GigabitEthernet7/1
Peer = 10.10.100.231
IP ACL = acl1
permit ip 10.10.100.232 255.255.255.255 10.10.100.231 255.255.255.255
Transform-sets: tfs-02,
Security Association Lifetime: 3000 gigabytes/120 seconds
PFS (Y/N): Y
PFS Group: group5
GigabitEthernet1/2
will negotiate {tunnel}
will negotiate {tunnel}
will negotiate {tunnel}
will negotiate {tunnel}
will negotiate {tunnel}
will negotiate {tunnel}
Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x
IPsec Issues
Figure 22-1
Step 2
through
Step
7.
22-7

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents