S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
35-22
Cisco MDS 9000 Family CLI Configuration Guide
OL-16184-01, Cisco MDS SAN-OS Release 3.x
Chapter 35 Configuring IPsec Network Security
Crypto IPv4-ACLs
Table 35-2
provides a list of allowed transform combinations for IPsec.
Note
The following table lists the supported and verified settings for IPsec and IKE encryption authentication
algorithms on the Microsoft Windows and Linux platforms:
Configuring Transform Sets
To configure transform sets, follow these steps:
Table 35-2
IPsec Transform Configuration Parameters
Parameter
Accepted Values
Keyword
encryption algorithm
56-bit DES-CBC
168-bit DES
128-bit AES-CBC
128-bit AES-CTR
1
256-bit AES-CBC
256-bit AES-CTR
1
1.
If you configure the AES counter (CTR) mode, you must also configure the authentication algorithm.
esp-des
esp-3des
esp-aes 128
esp-aes 128 ctr
esp-
aes 256
esp-aes
256 ctr
hash/authentication algorithm
1
(optional)
SHA-1 (HMAC variant)
MD5 (HMAC variant)
AES-XCBC-MAC
esp-sha1-hmac
esp-md5-hmac
esp-
aes-xcbc-mac
Platform
IKE
IPsec
Microsoft iSCSI initiator,
Microsoft IPsec implementation
on Microsoft Windows 2000
platform
3DES, SHA-1 or MD5,
DH group 2
3DES, SHA-1
Cisco iSCSI initiator,
Free Swan IPsec implementation
on Linux platform
3DES, MD5, DH group 1
3DES, MD5
Command
Purpose
Step 1
switch#
config terminal
switch(config)#
Enters configuration mode.