Cisco Systems
C7200
manual
OL-9129-02
Troubleshooting
Install
Condition System is Configured
Creating Crypto Access Lists
Command Purpose
Connectors
Safety
Authorization
Submitting a Service Request
Features
Page 6
Contents
C7200 VSA (VPN Services Adapter) Installation and Configuration Guide
vi
OL-9129-02
Page 5
Page 7
Image 6
Page 5
Page 7
Contents
Corporate Headquarters
Text Part Number OL-9129-02
Page
N T E N T S
Preventing Electrostatic Discharge Damage 2
Creating Dynamic Crypto Maps 4
OL-9129-02
Preface
Audience
Objectives
Organization
Chapter Title Description
Related Documentation
Obtaining Documentation
Cisco.com
Documentation Feedback
Cisco Product Security Overview
Product Documentation DVD Ordering Documentation
Reporting Security Problems in Cisco Products
Product Alerts and Field Notices
Obtaining Technical Assistance
Cisco Technical Support & Documentation Website
Submitting a Service Request
Definitions of Service Request Severity
Obtaining Additional Publications and Information
Xiv
Overview
Data Encryption Overview
VSA Overview
Screws Handle Status LED light
VSA Module Front View
Feature Description/Benefit
Features
This section describes the VSA features, as listed in Table
Hardware Required
Standards
Supported Standards, MIBs, and RFCs
Performance
MIBs
Disabling the VSA during Operation
Command Purpose
Enabling/Disabling the VSA
Enabling/Disabling Scheme
Condition System is Configured
Command Description of VSA Behavior
LEDs
Slot Locations
Connectors
See -2for the VSA connectors
Cisco 7204VXR Router
Port adapter VSA in I/O controller slot Port adapter lever
Cisco 7204VXR Router Front View
Cisco 7206VXR Router
Cisco 7206VXR Front View
Required Tools and Equipment
Hardware and Software Requirements
Restrictions
Software Requirements
Hardware Requirements
Platform
Safety Guidelines
Safety Warnings
Online Insertion and Removal OIR
Electrical Equipment Guidelines
Preventing Electrostatic Discharge Damage
Preparing for Installation
OL-9129-02
Handling the VSA
VSA circuit board is sensitive to ESD damage
VSA Removal and Installation
This section describes how to remove and install the VSA
Removing and Installing the VSA VSA Removal and Installation
OL-9129-02
Configuration Tasks
Overview
Using the Exec Command Interpreter
Configuring an IKE Policy
Optional Specifies the authentication method within an IKE
Key Management Protocol Isakmp policy configuration
Config-isakmp mode
Signatures as the authentication method
Configuring a Transform Set
Disabling VSA Optional
Defining a Transform Set
Transform type Description
Crypto Transform Configuration Mode
IPSec Protocols AH and ESP
Selecting Appropriate Transforms
Setting Global Lifetimes for IPSec Security Associations
Configuring IPSec
Ensuring That Access Lists Are Compatible with IPSec
Changing Existing Transforms
Step Command Purpose
Creating Crypto Access Lists
Creating Crypto Map Entries
ESP authenticator algorithm
Only one transform set can be specified when IKE is
Authenticator keys if the transform set includes an
Exits crypto-map configuration mode and return to
Creating Dynamic Crypto Maps
If this is configured, the data flow identity proposed
Optional Accesses list number or name of an
Extended access list. This access list determines
For this crypto access list
Monitoring and Maintaining IPSec
Applying Crypto Map Sets to Interfaces
Verifying IKE and IPSec Configurations
Router# show crypto isakmp policy
Verifying the Configuration
Currentpeer 172.21.114.67 PERMIT, flags=originisacl
Configuring IPSec Configuration Example
Configuration Examples
Configuring IKE Policies Example
This section provides the following configuration examples
Basic IPSec Configuration Illustration
Router a Configuration
Crypto map is applied to an interface
Router B Configuration
Transform set defines how the traffic will be protected
Specify the parameters to be used during an IKE negotiation
Troubleshooting Tips
Router# show diag
Tunnel I/F
Using Deny Policies in Access Lists
Monitoring and Maintaining the VSA
Monitor and Maintenance Commands
Configuration Guidelines and Restrictions
D E
Sa command, clear crypto Entries, creating
Set pfs command
Set session-key command Set transform-set command
Features Handling Monitoring and maintaining 4 Overview
Handling VPN Acceleration Module see VAM 1
IN-4
Related pages
Troubleshooting for Kyocera FS-1128MFP
Specifications Supplemental Information Output Power Sweep for Agilent Technologies E4403B
Error messages for Acer 3020 Series
Diagram of AquaStar 38 B for AquaStar 38B LP
16Where to use a large Close box for Apple 2
Installing the Base Cover for Dell E7240
Parts List for Desa BLP155AT
Top
Page
Image
Contents