Optional Ike Parameter Configuration - HP Cisco MDS 9216 - Fabric Switch Configuration Manual

Cisco mds 9000 family fabric manager configuration guide, release 3.x (ol-8222-10, april 2008)
Hide thumbs Also See for Cisco MDS 9216 - Fabric Switch:
Table of Contents

Advertisement

Optional IKE Parameter Configuration

S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
Figure 44-10
Step 4
Enter the Priority for this switch. You can enter a value from one through 255, one being the highest.
Step 5
Select appropriate values for the encryption, hash, authentication, and DHGroup fields.
Step 6
Enter the lifetime for the policy. You can enter a lifetime from 600 to 86400 seconds.
Click Create to create this policy, or click Close to discard any unsaved changes.
Step 7
When the authentication method is rsa-sig, make sure the identity hostname is configured for IKE
Note
because the IKE certificate has a subject name of the FQDN type.
Optional IKE Parameter Configuration
You can optionally configure the following parameters for the IKE feature:
Cisco MDS 9000 Family CLI Configuration Guide
44-16
Create IKE
The lifetime association within each policy—The lifetime ranges from 600 to 86,400 seconds. The
default is 86,400 seconds (equals one day). The lifetime association within each policy is configured
when you are creating an IKE policy. See the
The keepalive time for each peer if you use IKEv2—The keepalive ranges from 120 to 86,400
seconds. The default is 3,600 seconds (equals one hour).
The initiator version for each peer—IKE v1 or IKE v2 (default). Your choice of initiator version
does not affect interoperability when the remote device initiates the negotiation. Configure this
option if the peer device supports IKEv1 and you can play the initiator role for IKE with the
specified device. Use the following considerations when configuring the initiator version with FCIP
tunnels:
If the switches on both sides of an FCIP tunnel are running MDS SAN-OS Release 3.0(1) or
later, you must configure initiator version IKEv1 on both sides of an FCIP tunnel to use only
IKEv1. If one side of an FCIP tunnel is using IKEv1 and the other side is using IKEv2, the FCIP
tunnel uses IKEv2.
If the switch on one side of an FCIP tunnel is running MDS SAN-OS Release 3.0(1) or later and
the switch on the other side of the FCIP tunnel is running MDS SAN-OS Release 2.x,
configuring IKEv1 on either side (or both) results in the FCIP tunnel using IKEv1.
Chapter 44
Configuring IPsec Network Security
"Configuring an IKE Policy" section on page
OL-16184-01, Cisco MDS SAN-OS Release 3.x
44-15.

Advertisement

Table of Contents
loading

Table of Contents