S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m .
Configuring IPsec Network Security
IP Security (IPsec) Protocol is a framework of open standards that provides data confidentiality, data
integrity, and data authentication between participating peers. It is developed by the Internet Engineering
Task Force (IETF). IPsec provides security services at the IP layer, including protecting one or more data
flows between a pair of hosts, between a pair of security gateways, or between a security gateway and a
host. The overall IPsec implementation is per the latest version of RFC2401. Cisco SAN-OS IPsec
implements RFC 2402 through RFC 2410.
IPsec uses the Internet Key Exchange (IKE) protocol to handle protocol and algorithm negotiation and
to generate the encryption and authentication keys to be used by IPsec. While IKE can be used with other
protocols, its initial implementation is with the IPsec protocol. IKE provides authentication of the IPsec
peers, negotiates IPsec security associations, and establishes IPsec keys. IKE uses RFCs 2408, 2409,
2410, 2412, and additionally, implements the draft-ietf-ipsec-ikev2-16.txt draft.
The term IPsec is sometimes used to describe the entire protocol of IPsec data services and IKE security
Note
protocols and is also sometimes used to describe only the data services.
This chapter includes the following sections:
About IPsec, page 30-2
•
•
About IKE, page 30-3
IPsec Prerequisites, page 30-3
•
IPsec Compatibility, page 30-4
•
IPsec and IKE Terminology, page 30-4
•
Supported IPsec Transforms and Algorithms, page 30-5
•
Supported IKE Transforms and Algorithms, page 30-6
•
Initializing IKE, page 30-7
•
Configuring the IKE Domain, page 30-7
•
About IKE Tunnels, page 30-7
•
•
IKE Policy Negotiation, page 30-7
Clearing IKE Tunnels or Domains, page 30-11
•
•
Refreshing SAs, page 30-11
Configuring IPsec, page 30-11
•
•
IPsec Maintenance, page 30-22
OL-6973-03, Cisco MDS SAN-OS Release 2.x
C H A P T E R
Cisco MDS 9000 Family Configuration Guide
30
30-1
Need help?
Do you have a question about the DS-X9530-SF1-K9 - Supervisor-1 Module - Control Processor and is the answer not in the manual?
Questions and answers