S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
35-3
Cisco MDS 9000 Family CLI Configuration Guide
OL-16184-01, Cisco MDS SAN-OS Release 3.x
Chapter 35 Configuring IPsec Network Security
About IKE
Figure 35-1
FCIP and iSCSI Scenarios Using MPS-14/2 Modules
About IKE
IKE automatically negotiates IPsec security associations and generates keys for all switches using the
IPsec feature. Specifically, IKE provides these benefits:
•
Allows you to refresh IPsec SAs.
•
Allows IPsec to provide anti-replay services.
•
Supports a manageable, scalable IPsec configuration.
•
Allows dynamic authentication of peers.
Note
IKE is not supported on the Cisco Fabric Switch for HP c-Class BladeSystem and the Cisco Fabric
Switch for IBM BladeSystem.
IPsec Prerequisites
To use the IPsec feature, you need to perform the following tasks:
•
Obtain the ENTERPRISE_PKG license (see
Chapter 3, “Obtaining and Installing Licenses”
).
•
Configure IKE as described in the
“About IKE Initialization” section on page 35-10
.
FC
FC
FC
FC
FC
FC
MDS_Switch1
WAN
WAN
MDS
iSCSI Servers
IPSec for
securing
FCIP traffic
IPSec for
securing
iSCSI traffic
FC Servers
iSCSI Servers
120481
MDS_Switch 2
MDS_Switch 3
IPsec for securing
traffic between
MDS and router
Nonsecure
connection
Secure
connection