S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
35-25
Cisco MDS 9000 Family CLI Configuration Guide
OL-16184-01, Cisco MDS SAN-OS Release 3.x
Chapter 35 Configuring IPsec Network Security
Crypto IPv4-ACLs
About SA Lifetime Negotiation
You can override the global lifetime values (size and time) by configuring an SA-specific lifetime value.
To specify SA lifetime negotiation values, you can optionally configure the lifetime value for a specified
crypto map. If you do, this value overrides the globally set values. If you do not specify the crypto map
specific lifetime, the global value (or global default) is used.
See the
“Global Lifetime Values” section on page 35-29
for more information on global lifetime values.
Setting the SA Lifetime
To set the SA lifetime for a specified crypto map entry, follow these steps:
Step 3
switch(config-crypto-map-ip)#
match
address SampleAcl
Names an ACL to determine which traffic should be
protected and not protected by IPsec in the context of
this crypto map entry.
switch(config-crypto-map-ip)#
no match
address SampleAcl
Deletes the matched address.
Step 4
switch(config-crypto-map-ip)#
set peer
10.1.1.1
Configures a specific peer IPv4 address.
Note
IKE only supports IPv4 addresses, not IPv6
addresses.
Step 5
switch(config-crypto-map-ip)#
no set
peer 10.1.1.1
Deletes the configured peer.
Step 6
switch(config-crypto-map-ip)#
set
transform-set SampleTransform1
SampleTransmfor2
Specifies which transform sets are allowed for the
specified crypto map entry or entries. List multiple
transform sets in order of priority (highest priority
first).
switch(config-(crypto-map-ip))#
no set
transform-set
Deletes the association of all transform sets
(regardless of you specifying a transform set name).
Command
Purpose
Command
Purpose
Step 1
switch#
config terminal
switch(config)#
Enters configuration mode.
Step 2
switch(config)#
crypto map domain ipsec
SampleMap 31
switch(config-crypto-map-ip)#
Enters crypto map configuration submode for the
entry named SampleMap with 31 as its sequence
number.
Step 3
switch(config-crypto-map-ip)#
set
security-association lifetime seconds
8640
Specifies an SA lifetime for this crypto map entry
using different IPsec SA lifetimes than the global
lifetimes for the crypto map entry.
switch(config-crypto-map-ip)#
no
set
security-association lifetime seconds
8640
Deletes the entry-specific configuration and reverts to
the global settings.
Содержание 9124 - Cisco MDS Fabric Switch
Страница 76: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 122: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 328: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 482: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 733: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m P A R T 5 Security ...
Страница 734: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 957: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m P A R T 6 IP Services ...
Страница 958: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 1182: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 1214: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 1307: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m P A R T 9 Traffic Management ...
Страница 1308: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 1331: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m P A R T 1 0 Troubleshooting ...
Страница 1332: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...