Cisco MDS 9000 Series Configuration Manual page 292

Security
Hide thumbs Also See for MDS 9000 Series:
Table of Contents

Advertisement

INDEX
185, 187, 188, 192
crypto IPv4-ACLs
any keyword
188
configuration guidelines
creating
188
creating crypto map entries
mirror images
187
crypto map entries
193, 197
configuring global lifetime values
197
global lifetime values
193
setting SA lifetimes
196
crypto map sets
applying to interfaces
196
crypto maps
191, 192, 193, 194, 195, 196
auto-peer option
194
configuration guidelines
configuring autopeer option
configuring perfect forward secrecy
192
creating entries
191
entries for IPv4-ACLs
perfect forward secrecy
SA lifetime negotiations
SAs between peers
191
D
Data Encryption Standard encryption. See DES encryption
DES encryption
172, 173
IKE
173
IPsec
172
DH
173
IKE
173
DHCHAP
211, 212, 213, 214, 216, 217, 218, 219, 220, 222, 223
AAA authenticationDHCHAP
configuring AAA authentication
214
authentication modes
compatibility with other SAN-OS features
configuring
212, 220
default settings
223
description
212
displaying security information
enabling
213
216
group settings
216
hash algorithms
212
licensing
passwords for local switches
passwords for remote devices
sample configuration
222
See also FC-SP[DHCHAP
zzz]
211
timeout values
219
Diffie-Hellman Challenge Handshake Authentication Protocol. See
DHCHAP
211
Diffie-Hellman protocol. See DH
digital certificates
117, 120, 121, 125, 126, 127, 128, 129, 130, 131, 138,
145, 153, 162, 173, 175
configuration example
131
Cisco MDS 9000 Series Security Configuration Guide, Release 8.x
IN-2
185
192
197
192
195
196
196
193
172
220
220
213
220
217
218
211
173
digital certificates (continued)
configuring
121, 130
129
deleting from CAs
117, 121
description
121, 127, 128
exporting
generating requests for identity certificates
121, 127, 128
importing
installing identity certificates
IPsec
173, 175
maintaining
127
maximum limits
153
monitoring
127
120
peers
117
purpose
requesting identity certificate example
145
revocation example
SSH support
162
digital signature algorithm. See DSA key pairs
dsa key pairs
156
generatingDSA key-pairs
generating
156
E
E ports
251
fabric binding checking
EFMD
251
251
fabric binding
25
encrypted passwords
25
user accounts
Exchange Fabric Membership Data. See EFMD
F
213, 251, 252, 255, 256, 257, 261
fabric binding
255
activation
251
checking for Ex ports
clearing statistics
257
compatibility with DHCHAP
configuration
252, 257
default settings
261
deleting database
257
description
251, 252
251
EFMD
252
enforcement
256
forceful activation
251
licensing requirements
port security comparison
saving configurations
257
verifying configuration
257
fabric security
211, 223
authentication
211
223
default settings
211, 213
FC-SP
211
authentication
125
126
138
156
156
251
251
213
251

Advertisement

Table of Contents
loading

Table of Contents