Cisco Systems C7200 manual Sa command, clear crypto Entries, creating, Set pfs command

Page 60

Index

I

IKE

 

 

configuring

1 - 6, 4 - 2

 

configuring policies example 4 - 18

insertion and removal, online

3 - 2

interpreter, EXEC command

4 - 2

IPSec

 

 

access lists

4 - 8

 

monitoring

4 - 16

 

transform sets

 

defining

4 - 5

 

IPSec (IPSec network security protocol)

configuring 4 - 14

crypto access lists 4 - 10 creating 4 - 10

crypto maps dynamic

O

online insertion and removal 3 - 2

P

prevention, ESD 2 - 4

R

removal, online insertion and

3 - 2

Required

2 - 1

 

required tools and equipment

2 - 1

requirements

 

hardware

2 - 2

 

RFCs 1 - 5

 

 

 

creating 4 - 12

 

S

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

definition

4 - 12

 

sa command, clear crypto

4 - 16

 

 

 

 

entries, creating

?? to 4 - 14

 

 

 

 

 

 

safety guidelines

2 - 3

 

 

 

 

 

transforms

 

 

 

 

 

 

 

 

 

 

 

 

 

safety warnings 2 - 3

 

 

 

 

 

allowed combinations

4 - 6

 

 

 

 

 

 

 

SAs (security associations)

 

 

 

 

 

changing

4 - 8

 

 

 

 

 

 

 

 

 

 

 

clearing 4 - 9, 4 - 14

 

 

 

 

 

selecting

4 - 7

 

 

 

 

 

 

 

 

 

 

 

lifetimes

 

 

 

 

 

IPSec, configuring

4 - 19

 

 

 

 

 

 

 

 

 

global values, configuring

4 - 8

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

set peer command

4 - 10, 4 - 11, 4 - 13

 

 

 

 

 

 

 

 

 

 

 

 

L

 

 

 

 

set pfs command

4 - 12, 4 - 13

 

 

 

LEDs

 

 

 

 

set security-association level per-host command 4 - 12

 

 

 

 

set security-association lifetime command

4 - 12, 4 - 13

 

 

SM-VAM

1 - 3, 1 - 8

 

 

 

 

 

 

set session-key command

4 - 11

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

set transform-set command

4 - 11, 4 - 12

 

 

 

 

 

 

 

 

 

 

M

 

 

 

 

show crypto dynamic-map command 4 - 15

 

 

maintenance, parts required for VIP installation and

2 - 1

show crypto ipsec sa command

4 - 15

 

 

show crypto ipsec security-association lifetime

match address command

4 - 11, 4 - 13

 

 

command

4 - 15

 

 

 

 

MIBs 1 - 5

 

 

 

 

show crypto ipsec transform-set command

4 - 15

 

module, VPN acceleration (see VSA) 1 - 1

 

show crypto map command

4 - 15

 

 

 

 

 

 

 

 

 

 

software

 

 

 

 

 

 

 

 

 

C7200 VSA (VPN Services Adapter) Installation and Configuration Guide

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

IN-2

 

 

 

 

 

 

 

 

 

 

OL-9129-02

 

 

 

 

 

 

 

 

 

 

 

 

 

Image 60
Contents Corporate Headquarters Text Part Number OL-9129-02Page N T E N T S Preventing Electrostatic Discharge Damage 2 Creating Dynamic Crypto Maps 4 OL-9129-02 Preface AudienceObjectives OrganizationChapter Title Description Related Documentation Obtaining DocumentationCisco.com Documentation Feedback Cisco Product Security OverviewProduct Documentation DVD Ordering Documentation Reporting Security Problems in Cisco Products Product Alerts and Field NoticesObtaining Technical Assistance Cisco Technical Support & Documentation WebsiteSubmitting a Service Request Definitions of Service Request SeverityObtaining Additional Publications and Information Xiv Overview Data Encryption OverviewVSA Overview Screws Handle Status LED light VSA Module Front ViewFeatures This section describes the VSA features, as listed in TableFeature Description/Benefit Hardware RequiredSupported Standards, MIBs, and RFCs PerformanceStandards MIBsCommand Purpose Enabling/Disabling the VSADisabling the VSA during Operation Enabling/Disabling SchemeCondition System is Configured Command Description of VSA BehaviorLEDs Connectors See -2for the VSA connectorsSlot Locations Cisco 7204VXR RouterPort adapter VSA in I/O controller slot Port adapter lever Cisco 7204VXR Router Front ViewCisco 7206VXR Router Cisco 7206VXR Front ViewRequired Tools and Equipment Hardware and Software RequirementsSoftware Requirements Hardware RequirementsRestrictions PlatformSafety Guidelines Safety WarningsOnline Insertion and Removal OIR Electrical Equipment Guidelines Preventing Electrostatic Discharge DamagePreparing for Installation OL-9129-02 Handling the VSA VSA circuit board is sensitive to ESD damageVSA Removal and Installation This section describes how to remove and install the VSARemoving and Installing the VSA VSA Removal and Installation OL-9129-02 Configuration Tasks OverviewUsing the Exec Command Interpreter Configuring an IKE PolicyKey Management Protocol Isakmp policy configuration Config-isakmp modeOptional Specifies the authentication method within an IKE Signatures as the authentication methodConfiguring a Transform Set Disabling VSA OptionalDefining a Transform Set Transform type Description Crypto Transform Configuration Mode IPSec Protocols AH and ESPSelecting Appropriate Transforms Configuring IPSec Ensuring That Access Lists Are Compatible with IPSecSetting Global Lifetimes for IPSec Security Associations Changing Existing TransformsStep Command Purpose Creating Crypto Access Lists Creating Crypto Map EntriesOnly one transform set can be specified when IKE is Authenticator keys if the transform set includes anESP authenticator algorithm Exits crypto-map configuration mode and return toCreating Dynamic Crypto Maps Optional Accesses list number or name of an Extended access list. This access list determinesIf this is configured, the data flow identity proposed For this crypto access listMonitoring and Maintaining IPSec Applying Crypto Map Sets to InterfacesVerifying IKE and IPSec Configurations Router# show crypto isakmp policyVerifying the Configuration Currentpeer 172.21.114.67 PERMIT, flags=originisacl Configuration Examples Configuring IKE Policies ExampleConfiguring IPSec Configuration Example This section provides the following configuration examplesBasic IPSec Configuration Illustration Router a ConfigurationCrypto map is applied to an interface Router B Configuration Transform set defines how the traffic will be protectedSpecify the parameters to be used during an IKE negotiation Troubleshooting Tips Router# show diagTunnel I/F Using Deny Policies in Access Lists Monitoring and Maintaining the VSAMonitor and Maintenance Commands Configuration Guidelines and RestrictionsD E Sa command, clear crypto Entries, creating Set pfs commandSet session-key command Set transform-set command Features Handling Monitoring and maintaining 4 Overview Handling VPN Acceleration Module see VAM 1IN-4