Send documentation comments to mdsfeedback-doc@cisco.com
44-34
Cisco MDS 9000 Family Fabric Manager Configuration Guide
OL-17256-03, Cisco MDS NX-OS Release 4.x
Chapter 44 Configuring IPsec Network Security
Crypto IPv4-ACLs
Figure 44-28 IPsec Configuration
Step 2 Click the CryptoMap Set Entry tab.
You see the existing crypto maps configured in Figure 44-29.
Figure 44-29 Existing Crypto Maps
Step 3 Check or uncheck the AutoPeer option for the selected crypto map set entry.
Step 4 Click Apply Changes to save your changes.
About Perfect Forward Secrecy
To specify SA lifetime negotiation values, you can also optionally configure the perfect forward secrecy
(PFS) value in the crypto map.
The PFS feature is disabled by default. If you set the PFS group, you can set one of the DH groups: 1,
2, 5, or 14. If you do not specify a DH group, the software uses group 1 by default.