S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
35-40
Cisco MDS 9000 Family CLI Configuration Guide
OL-16184-01, Cisco MDS SAN-OS Release 3.x
Chapter 35 Configuring IPsec Network Security
Sample iSCSI Configuration
Figure 35-9
iSCSI with End-to-End IPsec
To configure IPsec for the iSCSI scenario shown in
Figure 35-9
, follow these steps:
Step 1
Configure the ACLs in Switch MDS A.
sw10.1.1.100#
conf t
sw10.1.1.100(config)#
ip access-list acl1 permit tcp 10.10.1.0 0.0.0.255 range port 3260
3260 12.12.1.0 0.0.0.255
Step 2
Configure the transform set in Switch MDS A.
sw10.1.1.100(config)# crypto transform-set domain ipsec tfs-01 esp-3des esp-md5-hmac
Step 3
Configure the crypto map in Switch MDS A.
sw10.1.1.100(config)#
crypto map domain ipsec cmap-01 1
sw10.1.1.100(config-crypto-map-ip)#
match address acl1
sw10.1.1.100(config-crypto-map-ip)#
set peer auto-peer
sw10.1.1.100(config-crypto-map-ip)#
set transform-set tfs-01
sw10.1.1.100(config-crypto-map-ip)#
end
sw10.1.1.100#
Step 4
Bind the interface to the crypto map set in Switch MDS A.
sw10.1.1.100#
conf t
sw10.1.1.100(config)#
int gigabitethernet 7/1
sw10.1.1.100(config-if)#
ip address 10.10.1.123 255.255.255.0
sw10.1.1.100(config-if)#
crypto map domain ipsec cmap-01
sw10.1.1.100(config-if)#
no shut
sw10.1.1.100(config-if)#
end
sw10.1.1.100#
MDS A
iPSEC
iPSEC
iPSEC
12.12.1.10
Host 2
12.12.1.50
Host 3
12.12.1.11
Host 1
12.12.1.1
10.10.1.1
10.10.1.123
Router
iPSEC
120484
Subnet 12.12.1/24
Содержание 9124 - Cisco MDS Fabric Switch
Страница 76: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 122: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 328: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 482: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 733: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m P A R T 5 Security ...
Страница 734: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 957: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m P A R T 6 IP Services ...
Страница 958: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 1182: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 1214: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 1307: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m P A R T 9 Traffic Management ...
Страница 1308: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...
Страница 1331: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m P A R T 1 0 Troubleshooting ...
Страница 1332: ...Se n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a ck d o c c i s c o c o m ...