Chapter 4 Configuring the ISA and ISM

Using the EXEC Command Interpreter

Configuring IPSec requires privileged-level access to the EXEC command interpreter. Also, privileged-level access usually requires a password. (Contact your system administrator, if necessary, to obtain privileged-level access.)

These sections contain basic configuration information only. For detailed configuration information, refer to the “IP Security and Encryption” chapter of the Security Configuration Guide publication.

Using the EXEC Command Interpreter

You modify the configuration of your router through the software command interpreter called the EXEC (also called enable mode). You must enter the privileged level of the EXEC command interpreter with the enable command before you can use the configure command to configure a new interface or change the existing configuration of an interface. The system prompts you for a password if one has been set.

The system prompt for the privileged level ends with a pound sign (#) instead of an angle bracket (>). At the console terminal, use the following procedure to enter the privileged level:

Step 1 At the user-level EXEC prompt, enter the enable command. The EXEC prompts you for a privileged-level password as follows:

Router> enable

Password:

Step 2 Enter the password (the password is case sensitive). For security purposes, the password is not displayed.

When you enter the correct password, the system displays the privileged-level system prompt (#):

Router#

Enabling MPPE

Use the encryption mppe command in ISA controller configuration mode to enable MPPE on the ISA or the ISM. This off-loads the MPPE function from the route processor to the ISA or the ISM.

Note The boot LED remains lit instead of pulsating when the ISA/ISM is configured for IPSec (default). When the ISA/ISM is configured for MPPE, the Boot LED pulsates. The ISA/ISM functions normally whether the Boot LED is pulsating or is solid.

Note To use the encryption mppe command, PPP encapsulation must be enabled.

Step

Command

Purpose

 

 

 

1.

Router(config)# controller isa slot/port

Enter controller configuration mode on

 

 

the ISA card.

 

 

 

2.

Router(config-controller)# encryption mppe

Enables MPPE encryption.

 

 

 

Integrated Services Adapter and Integrated Services Module Installation and Configuration

4-2

OL-3575-01 B0

 

 

Page 38
Image 38
Cisco Systems SA-ISA Using the Exec Command Interpreter, Enabling Mppe, Enter controller configuration mode on, ISA card