S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
22-4
Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x
OL-9285-05
Chapter 22 Troubleshooting IPsec
Initial Troubleshooting Checklist
IPsec Allowed Transforms
Table 22-3
provides a list of allowed transform combinations for IPsec.
Initial Troubleshooting Checklist
Begin troubleshooting IPsec issues by checking the following issues:
Common Troubleshooting Tools in Fabric Manager
Choose
Switches > Security > IPsec
to access IPsec.
Choose
Switches > Security > IKE
to access IKE.
Table 22-3
IPsec Transform Configuration Parameters
Parameter
Accepted Values
Encryption algorithm
56-bit DES-CBC
168-bit DES
128-bit AES-CBC
128-bit AES-CTR
1
256-bit AES-CBC
256-bit AES-CTR
1
1.
If you configure the AES counter (CTR) mode, you must also configure the
authentication algorithm.
Hash/authentication algorithm
1
(optional)
SHA-1 (HMAC variant)
MD5 (HMAC variant)
AES-XCBC-MAC
Checklist
Check off
Verify licensing requirements. See
Cisco MDS 9000 Family Fabric Manager
Configuration Guide
.
Verify that IKE has been configured for IPsec.
Verify the digital certificates configuration if it is enabled for IPsec. See
Chapter 24,
“Troubleshooting Digital Certificates.”
Verify that there are matching IKE policies defined at each peer.
Verify that you have refreshed SAs after any IKEv2 reconfiguration.
Verify that you have configured mirror crypto map ACLs at the peer for every crypto map
ACL configured locally.