Clearing Ike Tunnels Or Domains; Refreshing Sas; Configuring Ipsec; Crypto Acls - Cisco DS-X9530-SF1-K9 - Supervisor-1 Module - Control Processor Configuration Manual

Mds 9000 family
Table of Contents

Advertisement

Chapter 30
Configuring IPsec Network Security
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m .

Clearing IKE Tunnels or Domains

If a IKE tunnel ID is not specified for the IKE configuration, you can clear all existing IKE domain
connections by issuing the clear crypto ike domain ipsec sa command in EXEC mode.
switch# clear crypto ike domain ipsec sa
When you delete all the SAs within a specific IKEv2 tunnel, then that IKE tunnel is automatically
Caution
deleted.
If an SA is specified for the IKE configuration, you can clear the specified IKE tunnel ID connection by
issuing the clear crypto ike domain ipsec sa IKE_tunnel-ID command in EXEC mode.
switch# clear crypto ike domain ipsec sa 51
When you delete the IKEv2 tunnel, the associated IPsec tunnel under that IKE tunnel is automatically
Caution
deleted.

Refreshing SAs

Use the crypto ike domain ipsec rekey sa sa-index command to refresh the SAs after performing IKEv2
configuration changes.

Configuring IPsec

IPsec provides secure data flows between participating peers. Multiple IPsec data flows can exist
between two peers to secure different data flows, with each tunnel using a separate set of SAs.
After you have completed IKE configuration, configure IPsec.
To configure IPsec in each participating IPsec peer, follow these steps:
Identify the peers for the traffic to which secure tunnels should be established.
Step 1
Configure the transform set with the required protocols and algorithms.
Step 2
Create the crypto map and apply Access Control Lists (ACLs), transform set, peer, lifetime values as
Step 3
applicable.
Apply the crypto map to the required interface.
Step 4

Crypto ACLs

IP Access Control Lists (IP-ACLs) provide basic network security to all switches in the Cisco MDS 9000
Family. IP-ACLs restrict IP-related traffic based on the configured IP filters. Refer to the
Control Lists" section on page 29-1
OL-6973-03, Cisco MDS SAN-OS Release 2.x
for details on creating and defining IP-ACLs.
Cisco MDS 9000 Family Configuration Guide
Clearing IKE Tunnels or Domains
"IP Access
30-11

Advertisement

Table of Contents
loading

Table of Contents