Cisco TrustSec Configuration Manual page 93

Table of Contents

Advertisement

Chapter 7
Cisco TrustSec Command Summary
cts cache
To enable caching of TrustSec authorization and environment data information to DRAM and NVRAM,
use the cts cache global configuration command. Use the no form of the command to disable caching.
Syntax Description
enable
nv-storage
bootflash: dir
disk0: dir
disk1: dir
sup-bootflash: image
Defaults
The default is caching disabled.
Command Modes
Global configuration (config)
Supported User Roles
Administrator
Command History
Release
12.2(33) SXI
12.2(50) SY
Usage Guidelines
The cts cache command enables caching of authentication, authorization and environment-data
information to DRAM. Caching is for the maintenance and reuse of information obtained through
authentication and authorization. Keystore provides for secure storage of a device's own credentials
(passwords, certificates, PACs) either in software or on a specialized hardware component. In the
absence of a dedicated hardware keystore, a software emulation keystore is created using DRAM and
NVRAM.
Cisco TrustSec creates a secure cloud of devices in a network by requiring that each device authenticate
and authorize its neighbors with a trusted AAA server (Cisco Secure ACS 5.1 or more recent) before
being granted access to the TrustSec network. Once the authentication and authorization is complete, the
information could be valid for some time. If caching is enabled, that information can be reused, allowing
the network device to bring up links without having to connect with the ACS, thus expediting the
OL-22192-01
[no] cts cache {
enable |
nv-storage {bootflash: [
}
Enables CTS cache support
Causes DRAM cache updates to be written to non-volatile storage and
enables DRAM cache to be initially populated from nv-storage when the
network device boots.
Specifies bootflash dir as the nv-storage location.
Specifies disk 0 directory as the nv-storage location.
Specifies disk 1 directory as the nv-storage location.
Specifies a supervisor bootflash directory as the nv-storage location.
Modification
This command was introduced on the Catalyst 6500 series switches.
PMK caching support is added for the Catalyst 6500 series switches.
] | disk0: [dir] | disk1: [dir] | sup-bootflash: [image]}
dir
Cisco TrustSec Configuration Guide
cts cache
7-7

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents