Cisco DS-X9530-SF1-K9 - Supervisor-1 Module - Control Processor Configuration Manual page 674

Mds 9000 family
Table of Contents

Advertisement

Configuring IPsec
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m .
Table 30-2
Table 30-2
Parameter
encryption algorithm
hash/authentication algorithm
(optional)
1. If you configure the AES counter (CTR) mode, you must also configure the authentication algorithm.
The following table lists the supported and verified settings for IPSec and IKE encryption authentication
Note
algorithms on the Microsoft Windows and Linux platforms:
Platform
Microsoft iSCSI initiator,
Microsoft IPSec implementation
on Microsoft Windows 2000
platform
Cisco iSCSI initiator,
Free Swan IPSec implementation
on Linux platform
To configure transform sets, follow these steps:
Command
Step 1
switch# config terminal
switch(config)#
Step 2
switch(config)# crypto transform-set
domain ipsec test esp-3des esp-md5-hmac
switch(config)# no crypto transform-set
domain ipsec test esp-3des esp-md5-hmac
switch(config)# crypto transform-set
domain ipsec test esp-3des
switch(config)# no crypto transform-set
domain ipsec test esp-3des
Cisco MDS 9000 Family Configuration Guide
30-16
provides a list of allowed transform combinations for IPsec.
IPsec Transform Configuration Parameters
1
IKE
3DES, SHA-1 or MD5,
DH group 2
3DES, MD5, DH group 1
Chapter 30
Accepted Values
56-bit DES-CBC
168-bit DES
128-bit AES-CBC
1
128-bit AES-CTR
256-bit AES-CBC
1
256-bit AES-CTR
SHA-1 (HMAC variant)
MD5 (HMAC variant)
AES-XCBC-MAC
Purpose
Enters configuration mode.
Configures a transform set called test specifying the
3DES encryption algorithm and the MD5
authentication algorithm. Refer to
verify the allowed transform combinations.
Deletes the applied transform set.
Configures a transform set called test specifying the
3DES encryption algorithm. In this case, the default
no authentication is performed.
Deletes the applied transform set.
Configuring IPsec Network Security
Keyword
esp-des
esp-3des
esp-aes 128
esp-aes 128 ctr
esp-aes 256
esp-aes 256 ctr
esp-sha1-hmac
esp-md5-hmac
esp-aes-xcbc-mac
IPsec
3DES, SHA-1
3DES, MD5
Table 30-2
OL-6973-03, Cisco MDS SAN-OS Release 2.x
to

Advertisement

Table of Contents
loading

Table of Contents