Troubleshooting Guide
Page 449
...is a framework of security gateways, or between participating peers. IPsec provides security services at the IP layer, including protecting one or more information on the Cisco MDS 9216i Switch. • The IPsec feature is not supported on the management interface. It was developed by ...the Internet Engineering Task Force (IETF). It includes the following Cisco MDS 9000 Family hardware: • Cisco 14/2-port Multiprotocol Services (MPS-14/2) modules in Cisco MDS 9200 switches or Cisco MDS 9500 directors • Cisco MDS 9216i Switch with the MPS-14/2 capability in the integrated ...
...is a framework of security gateways, or between participating peers. IPsec provides security services at the IP layer, including protecting one or more information on the Cisco MDS 9216i Switch. • The IPsec feature is not supported on the management interface. It was developed by ...the Internet Engineering Task Force (IETF). It includes the following Cisco MDS 9000 Family hardware: • Cisco 14/2-port Multiprotocol Services (MPS-14/2) modules in Cisco MDS 9200 switches or Cisco MDS 9500 directors • Cisco MDS 9216i Switch with the MPS-14/2 capability in the integrated ...
Troubleshooting Guide
Page 458
... Internet address is 10.10.100.232/24 MTU 1500 bytes Port mode is IPS Speed is 1 Gbps Beacon is turned off 22-10 Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x OL-9285-05 The command outputs follow : MDSA# show interface gigabitethernet 7/1 GigabitEthernet7/1 is up Hardware...() Using Profile id 1 (interface GigabitEthernet7/1) Peer Information Peer Internet address is 10.10.100.232 and port is 3225 FCIP tunnel is protected by IPSec Write acceleration mode is off Auto-Negotiation is using the correct profile, the peer internet addresses are configured correctly, and the FCIP ...
... Internet address is 10.10.100.232/24 MTU 1500 bytes Port mode is IPS Speed is 1 Gbps Beacon is turned off 22-10 Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x OL-9285-05 The command outputs follow : MDSA# show interface gigabitethernet 7/1 GigabitEthernet7/1 is up Hardware...() Using Profile id 1 (interface GigabitEthernet7/1) Peer Information Peer Internet address is 10.10.100.232 and port is 3225 FCIP tunnel is protected by IPSec Write acceleration mode is off Auto-Negotiation is using the correct profile, the peer internet addresses are configured correctly, and the FCIP ...
Troubleshooting Guide
Page 459
Chapter 22 Troubleshooting IPsec IPsec Issues Send documentation comments to mdsfeedback-doc@cisco.com Tape acceleration mode is off Tape Accelerator flow control buffer size is automatic IP Compression is disabled Special Frame is disabled Maximum ...Trunk vsans (initializing) () Using Profile id 1 (interface GigabitEthernet1/2) Peer Information Peer Internet address is 10.10.100.231 and port is 3225 FCIP tunnel is protected by IPSec Write acceleration mode is off Tape acceleration mode is off Tape Accelerator flow control buffer size is automatic IP Compression is disabled Special...
Chapter 22 Troubleshooting IPsec IPsec Issues Send documentation comments to mdsfeedback-doc@cisco.com Tape acceleration mode is off Tape Accelerator flow control buffer size is automatic IP Compression is disabled Special Frame is disabled Maximum ...Trunk vsans (initializing) () Using Profile id 1 (interface GigabitEthernet1/2) Peer Information Peer Internet address is 10.10.100.231 and port is 3225 FCIP tunnel is protected by IPSec Write acceleration mode is off Tape acceleration mode is off Tape Accelerator flow control buffer size is automatic IP Compression is disabled Special...
Troubleshooting Guide
Page 460
... show crypto sad domain ipsec interface:GigabitEthernet1/2 Crypto map tag:cmap-01, local addr. 10.10.100.232 protected network: local ident (addr/mask):(10.10.100.232/255.255.255.255) remote ident (addr/mask):(10....:10.10.100.232, remote crypto endpt.:10.10.100.231 22-12 Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x OL-9285-05 IPsec Issues Chapter 22 Troubleshooting IPsec Send documentation... comments to mdsfeedback-doc@cisco.com 2 Active TCP connections Control connection:Local 10.10.100.232:65492, Remote 10.10...
... show crypto sad domain ipsec interface:GigabitEthernet1/2 Crypto map tag:cmap-01, local addr. 10.10.100.232 protected network: local ident (addr/mask):(10.10.100.232/255.255.255.255) remote ident (addr/mask):(10....:10.10.100.232, remote crypto endpt.:10.10.100.231 22-12 Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x OL-9285-05 IPsec Issues Chapter 22 Troubleshooting IPsec Send documentation... comments to mdsfeedback-doc@cisco.com 2 Active TCP connections Control connection:Local 10.10.100.232:65492, Remote 10.10...
Troubleshooting Guide
Page 476
... checking. Generate a certificate request in standard PEM (base64) format. Associate the RSA key pair to the CA. 24-2 Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x OL-9285-05 Peer Certificate Verification The peer certificate verification process involves the following steps...: 1. The information in the password-protected PKCS#12 standard format. Overview Chapter 24 Troubleshooting Digital Certificates Send documentation comments to mdsfeedback-doc@cisco.com RSA Key Pairs and Identity Certificates You can generate one or...
... checking. Generate a certificate request in standard PEM (base64) format. Associate the RSA key pair to the CA. 24-2 Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x OL-9285-05 Peer Certificate Verification The peer certificate verification process involves the following steps...: 1. The information in the password-protected PKCS#12 standard format. Overview Chapter 24 Troubleshooting Digital Certificates Send documentation comments to mdsfeedback-doc@cisco.com RSA Key Pairs and Identity Certificates You can generate one or...