Optional Ike Parameter Configuration - Cisco AP776A - Nexus Converged Network Switch 5020 Configuration Manual

Cisco mds 9000 family cli configuration guide - release 4.x (ol-18084-01, february 2009)
Hide thumbs Also See for AP776A - Nexus Converged Network Switch 5020:
Table of Contents

Advertisement

Optional IKE Parameter Configuration

S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
Command
Step 9
switch(config-ike-ipsec-policy)# authentication
pre-share
switch(config-ike-ipsec-policy)# authentication
rsa-sig
switch(config-ike-ipsec-policy)# no
authentication
When the authentication method is rsa-sig, make sure the identity hostname is configured for IKE
Note
because the IKE certificate has a subject name of the FQDN type.
Optional IKE Parameter Configuration
You can optionally configure the following parameters for the IKE feature:
Note
Caution
Cisco MDS 9000 Family CLI Configuration Guide
37-14
The lifetime association within each policy—The lifetime ranges from 600 to 86,400 seconds. The
default is 86,400 seconds (equals one day). The lifetime association within each policy is configured
when you are creating an IKE policy. See the
The keepalive time for each peer if you use IKEv2—The keepalive ranges from 120 to 86,400
seconds. The default is 3,600 seconds (equals one hour).
The initiator version for each peer—IKE v1 or IKE v2 (default). Your choice of initiator version
does not affect interoperability when the remote device initiates the negotiation. Configure this
option if the peer device supports IKEv1 and you can play the initiator role for IKE with the
specified device. Use the following considerations when configuring the initiator version with FCIP
tunnels:
If the switches on both sides of an FCIP tunnel are running MDS SAN-OS Release 3.0(1) or
later, or Cisco NX-OS 4.1(1) you must configure initiator version IKEv1 on both sides of an
FCIP tunnel to use only IKEv1. If one side of an FCIP tunnel is using IKEv1 and the other side
is using IKEv2, the FCIP tunnel uses IKEv2.
If the switch on one side of an FCIP tunnel is running MDS SAN-OS Release 3.0(1) or later, or
Cisco NX-OS 4.1(1b) and the switch on the other side of the FCIP tunnel is running MDS
SAN-OS Release 2.x, configuring IKEv1 on either side (or both) results in the FCIP tunnel
using IKEv1.
Only IKE v1 is supported to build IPsec between 2.x and 3.x MDS switches.
You may need to configure the initiator version even when the switch does not behave as an
IKE initiator under normal circumstances. Always using this option guarantees a faster
recovery of traffic flows in case of failures.
Chapter 37
Configuring IPsec Network Security
Purpose
Configures the authentication method to use
the preshared key (default).
Configures the authentication method to use
the RSA signature.
To use RSA signatures for
Note
authentication you must configure
identity authentication mode using the
FQDN (see
Reverts to the default (pre-share).
"Configuring an IKE Policy" section on page
OL-18084-01, Cisco MDS NX-OS Release 4.x
Step
3).
37-13.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents