Troubleshooting Guide
Page 449
...It was developed by the Internet Engineering Task Force (IETF). IPsec provides security services at the IP layer, including protecting one or more information on the management interface. Refer to troubleshoot IP security (IPsec) and Internet Key Exchange (IKE) encryption in the... Cisco MDS 9000 Family. OL-9285-05 Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x 22-1 It includes the following Cisco MDS 9000 Family hardware: • Cisco 14/2-port Multiprotocol Services (MPS-14/2) modules in Cisco MDS 9200 switches or Cisco MDS 9500 directors • Cisco MDS 9216i...
...It was developed by the Internet Engineering Task Force (IETF). IPsec provides security services at the IP layer, including protecting one or more information on the management interface. Refer to troubleshoot IP security (IPsec) and Internet Key Exchange (IKE) encryption in the... Cisco MDS 9000 Family. OL-9285-05 Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x 22-1 It includes the following Cisco MDS 9000 Family hardware: • Cisco 14/2-port Multiprotocol Services (MPS-14/2) modules in Cisco MDS 9200 switches or Cisco MDS 9500 directors • Cisco MDS 9216i...
Troubleshooting Guide
Page 458
...Using Profile id 1 (interface GigabitEthernet7/1) Peer Information Peer Internet address is 10.10.100.232 and port is 3225 FCIP tunnel is protected by IPSec Write acceleration mode is using the correct profile, the peer internet addresses are configured correctly, and the FCIP tunnels are ...follow : MDSA# show interface gigabitethernet command on both switches. IPsec Issues Chapter 22 Troubleshooting IPsec Send documentation comments to mdsfeedback-doc@cisco.com Step 1 Issue the show interface fcip 1 fcip1 is trunking Hardware is GigabitEthernet Port WWN is 21:90:00:0d:ec...
...Using Profile id 1 (interface GigabitEthernet7/1) Peer Information Peer Internet address is 10.10.100.232 and port is 3225 FCIP tunnel is protected by IPSec Write acceleration mode is using the correct profile, the peer internet addresses are configured correctly, and the FCIP tunnels are ...follow : MDSA# show interface gigabitethernet command on both switches. IPsec Issues Chapter 22 Troubleshooting IPsec Send documentation comments to mdsfeedback-doc@cisco.com Step 1 Issue the show interface fcip 1 fcip1 is trunking Hardware is GigabitEthernet Port WWN is 21:90:00:0d:ec...
Troubleshooting Guide
Page 459
Chapter 22 Troubleshooting IPsec IPsec Issues Send documentation comments to mdsfeedback-doc@cisco.com Tape acceleration mode is off Tape Accelerator flow control buffer size is automatic IP Compression is disabled Special Frame is disabled Maximum ...Trunk vsans (initializing) () Using Profile id 1 (interface GigabitEthernet1/2) Peer Information Peer Internet address is 10.10.100.231 and port is 3225 FCIP tunnel is protected by IPSec Write acceleration mode is off Tape acceleration mode is off Tape Accelerator flow control buffer size is automatic IP Compression is disabled Special...
Chapter 22 Troubleshooting IPsec IPsec Issues Send documentation comments to mdsfeedback-doc@cisco.com Tape acceleration mode is off Tape Accelerator flow control buffer size is automatic IP Compression is disabled Special Frame is disabled Maximum ...Trunk vsans (initializing) () Using Profile id 1 (interface GigabitEthernet1/2) Peer Information Peer Internet address is 10.10.100.231 and port is 3225 FCIP tunnel is protected by IPSec Write acceleration mode is off Tape acceleration mode is off Tape Accelerator flow control buffer size is automatic IP Compression is disabled Special...
Troubleshooting Guide
Page 460
....:10.10.100.232, remote crypto endpt.:10.10.100.231 22-12 Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x OL-9285-05 IPsec Issues Chapter 22 Troubleshooting IPsec Send documentation... comments to mdsfeedback-doc@cisco.com 2 Active TCP connections Control connection:Local 10.10.100.232:65492, Remote 10.... show crypto sad domain ipsec interface:GigabitEthernet7/1 Crypto map tag:cmap-01, local addr. 10.10.100.231 protected network: local ident (addr/mask):(10.10.100.231/255.255.255.255) remote ident (addr/mask):(10...
....:10.10.100.232, remote crypto endpt.:10.10.100.231 22-12 Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x OL-9285-05 IPsec Issues Chapter 22 Troubleshooting IPsec Send documentation... comments to mdsfeedback-doc@cisco.com 2 Active TCP connections Control connection:Local 10.10.100.232:65492, Remote 10.... show crypto sad domain ipsec interface:GigabitEthernet7/1 Crypto map tag:cmap-01, local addr. 10.10.100.231 protected network: local ident (addr/mask):(10.10.100.231/255.255.255.255) remote ident (addr/mask):(10...
Troubleshooting Guide
Page 476
... Send documentation comments to mdsfeedback-doc@cisco.com RSA Key Pairs and Identity Certificates You can generate one of a subordinate CA) and the identity certificates can be imported in standard PEM (base64) format. CRLs are published in the password-protected PKCS#12 standard format. Otherwise,...trusted CAs. • Verifies that the peer certificate is considered to be exported to the CA. 24-2 Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x OL-9285-05 Cisco MDS SAN-OS allows the manual configuration of these methods to current time. • Verifies that the ...
... Send documentation comments to mdsfeedback-doc@cisco.com RSA Key Pairs and Identity Certificates You can generate one of a subordinate CA) and the identity certificates can be imported in standard PEM (base64) format. CRLs are published in the password-protected PKCS#12 standard format. Otherwise,...trusted CAs. • Verifies that the peer certificate is considered to be exported to the CA. 24-2 Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x OL-9285-05 Cisco MDS SAN-OS allows the manual configuration of these methods to current time. • Verifies that the ...