Manually Configuring Ipsec And Ike; About Ike Initialization; About The Ike Domain; About Ike Tunnels - HP Cisco MDS 9216 - Fabric Switch Configuration Manual

Cisco mds 9000 family fabric manager configuration guide, release 3.x (ol-8222-10, april 2008)
Hide thumbs Also See for Cisco MDS 9216 - Fabric Switch:
Table of Contents

Advertisement

Chapter 44
Configuring IPsec Network Security
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m

Manually Configuring IPsec and IKE

This section describes how to manually configure IPsec and IKE if you are not using the FCIP Wizard.
See
IPsec provides secure data flows between participating peers. Multiple IPsec data flows can exist
between two peers to secure different data flows, with each tunnel using a separate set of SAs.
After you have completed IKE configuration, configure IPsec.
To configure IPsec in each participating IPsec peer, follow these steps:
Step 1
Identify the peers for the traffic to which secure tunnels should be established.
Step 2
Configure the transform set with the required protocols and algorithms.
Step 3
Create the crypto map and apply access control lists (IPv4-ACLs), transform sets, peers, and lifetime
values as applicable.
Step 4
Apply the crypto map to the required interface.
This section contains the following topics:

About IKE Initialization

The IKE feature must first be enabled and configured so the IPsec feature can establish data flow with
the required peer. Fabric Manager initializes IKE when you first configure it.
You cannot disable IKE if IPsec is enabled. If you disable the IKE feature, the IKE configuration is
cleared from the running configuration.

About the IKE Domain

You must apply the IKE configuration to an IPsec domain to allow traffic to reach the supervisor module
in the local switch. Fabric Manager sets the IPsec domain automatically when you configure IKE.

About IKE Tunnels

An IKE tunnel is a secure IKE session between two endpoints. IKE creates this tunnel to protect IKE
messages used in IPsec SA negotiations.
Two versions of IKE are used in the Cisco SAN-OS implementation.
OL-16184-01, Cisco MDS SAN-OS Release 3.x
Configuring IPsec Using FCIP Wizard, page
About IKE Initialization, page 44-13
About the IKE Domain, page 44-13
About IKE Tunnels, page 44-13
About IKE Policy Negotiation, page 44-14
Configuring an IKE Policy, page 44-15
IKE version 1 (IKEv1) is implemented using RFC 2407, 2408, 2409, and 2412.
Manually Configuring IPsec and IKE
44-10.
Cisco MDS 9000 Family CLI Configuration Guide
44-13

Advertisement

Table of Contents
loading

Table of Contents