Ipsec Maintenance; Global Lifetime Values - Cisco AP775A - Nexus Converged Network Switch 5010 Configuration Manual

Fabric manager configuration guide, release 4.x
Hide thumbs Also See for AP775A - Nexus Converged Network Switch 5010:
Table of Contents

Advertisement

Chapter 44
Configuring IPsec Network Security
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
Click the Interfaces tab.
Step 2
You see the existing interface to crypto map configuration in
Figure 44-33
Select the switch and interface you want to configure.
Step 3
Enter the name of the crypto map that you want to apply to this interface in the CryptomapSetName field.
Step 4
Click Create to apply the crypto map to the selected interface or click Close to exit the dialog box
Step 5
without applying the crypto map.

IPsec Maintenance

Certain configuration changes will only take effect when negotiating subsequent security associations.
If you want the new settings to take immediate effect, you must clear the existing security associations
so that they will be reestablished with the changed configuration. If the switch is actively processing
IPsec traffic, it is desirable to clear only the portion of the security association database that would be
affected by the configuration changes (that is, clear only the security associations established by a given
crypto map set). Clearing the full security association database should be reserved for large-scale
changes, or when the router is processing very little other IPsec traffic.

Global Lifetime Values

If you have not configured a lifetime in the crypto map entry, the global lifetime values are used when
negotiating new IPsec SAs.
You can configure two lifetimes: timed or traffic-volume. An SA expires after the first of these lifetimes
is reached. The default lifetimes are 3,600 seconds (one hour) and 450 GB.
If you change a global lifetime, the new lifetime value will not be applied to currently existing SAs, but
will be used in the negotiation of subsequently established SAs. If you wish to use the new values
immediately, you can clear all or part of the SA database.
OL-17256-03, Cisco MDS NX-OS Release 4.x
Crypto Map Interfaces
Cisco MDS 9000 Family Fabric Manager Configuration Guide
IPsec Maintenance
Figure
44-33.
44-37

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents