About Ike; Ipsec Prerequisites - Cisco DS-X9530-SF1-K9 - Supervisor-1 Module - Control Processor Configuration Manual

Mds 9000 family
Table of Contents

Advertisement

Chapter 30
Configuring IPsec Network Security
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m .
Figure 30-1

About IKE

IKE automatically negotiates IPsec security associations and generates keys for all switches using the
IPsec feature. Specifically, IKE provides these benefits:

IPsec Prerequisites

To use the IPsec feature, you need to perform the following tasks:
The IPsec feature inserts new headers in existing packets (see
Note
section on page 37-6
OL-6973-03, Cisco MDS SAN-OS Release 2.x
FCIP and iSCSI Scenarios Using MPS-14-2 Modules
IPSec for
securing
iSCSI traffic
MDS_Switch1
FC
FC
FC Servers
iSCSI Servers
Allows you to refresh IPsec SAs.
Allows IPsec to provide anti-replay services.
Supports a manageable, scalable IPsec configuration.
Allows dynamic authentication of peers.
Obtain the ENTERPRISE_PKG license (see
Configure IKE as described in the
for more information).
iSCSI Servers
IPSec for
securing
FCIP traffic
MDS_Switch 2
WAN
IPsec for securing
traffic between
MDS and router
WAN
Chapter 3, "Obtaining and Installing
"Initializing IKE" section on page
Cisco MDS 9000 Family Configuration Guide
FC
FC
FC
MDS_Switch 3
FC
FC
FC
MDS
Nonsecure
connection
Secure
connection
Licenses").
30-7.
"Configuring the MTU Frame Size"
About IKE
30-3

Advertisement

Table of Contents
loading

Table of Contents