Cisco MDS 9000 Series Configuration Manual page 289

Security
Hide thumbs Also See for MDS 9000 Series:
Table of Contents

Advertisement

Configuring Cisco TrustSec Fibre Channel Link Encryption
fcsp authentication mode:SEC_MODE_ON
ESP is enabled
configured mode is: GMAC
programmed ingress SA: 256, 257
programmed egress SA: 256
Status:Successfully authenticated
Authenticated using local password database
Statistics:
FC-SP Authentication Succeeded:17
FC-SP Authentication Failed:3
FC-SP Authentication Bypassed:0
FC-SP ESP SPI Mismatched frames:0
FC-SP ESP Auth failed frames:0
Cisco TrustSec FC Link Encryption Best Practices
Best practices are the recommended steps that should be taken to ensure the proper operation of Cisco TrustSec
FC Link Encryption.
This section covers the following topics:
General Best Practices
This section lists the general best practices for Cisco TrustSec FC Link Encryption:
• Ensure that Cisco TrustSec FC Link Encryption is enabled only between MDS switches. This feature is
• Ensure that the peers in the connection have the same configurations. If there are differences in the
• Before applying the SA to the ingress and egress hardware of a switch interface, ensure that the interface
Best Practices for Changing Keys
After the SA is applied to the ingress and egress ports, you should change the keys periodically in the
configuration. The keys should be changed sequentially to avoid traffic disruption.
As an example, consider that a security association has been created between two switches, Switch1 and
Switch2. The SA is configured on the ingress and egress ports as shown in the following example:
switch# configure terminal
switch(config)# interface fc1/1
switch(config-if)# fcsp esp manual
switch(config-if)# ingress-sa 256
switch(config-if)# egress-sa 256
To change the keys for these switches, follow these steps:
Procedure
Step 1
Add a new SA on Switch1 and Switch2.
supported only on E-ports or the ISLs, and errors will result if non-MDS switches are used.
configurations, a "port re-init limit exceeded" error message is displayed.
is in the admin shut mode.
Cisco TrustSec FC Link Encryption Best Practices
Cisco MDS 9000 Series Security Configuration Guide, Release 8.x
271

Advertisement

Table of Contents
loading

Table of Contents