EasyManua.ls Logo

Cisco IOS XR User Manual

Cisco IOS XR
254 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #126 background imageLoading...
Page #126 background image
Implementing IPSec Network Security on Cisco IOS XR Software
How to Implement General IPSec Configurations for IPSec Networks
SC-114
Cisco IOS XR System Security Configuration Guide
Configuring the DF Bit for the Encapsulating Header in IPSec Tunnels
This task configures the DF bit for the encapsulating header in IPSec tunnels. The DF bit configuration
is also specified for both service-ipsec and service-gre interfaces.
Note This IPSec feature is supported only on the Cisco IPSec VPN SPA.
SUMMARY STEPS
1. configure
2. crypto ipsec df-bit {clear | set | copy}
3. end
or
commit
DETAILED STEPS
Step 17
show crypto ipsec sa [sa-id | peer
ip-address
|
profile
profile-name
| detail | fvrf
fvrf-name
| ivrf
ivrf-name
| location
location
]
Example:
RP/0/0/CPU0:router# show crypto ipsec sa peer
172.19.72.120
(Optional) Displays SA information based on the
rack/slot/instance location.
• Use the optional detail keyword to display additional
dynamic SA information. The detail keyword is used
only for software-based SAs. SAs that are configured
under the tunnel-ipsec interface or crypto transport.
Step 18
show crypto ipsec summary
Example:
RP/0/0/CPU0:router# show crypto ipsec summary
(Optional) Displays IPSec summary information.
Command or Action Purpose
Command or Action Purpose
Step 1
configure
Example:
RP/0/0/CPU0:router# configure
Enters global configuration mode.
Step 2
crypto ipsec df-bit {clear | set | copy}
Example:
RP/0/0/CPU0:router(config)# crypto ipsec df-bit
clear
or
Sets the DF bit for the encapsulating header in IPSec
tunnels to all interfaces. You must specify at least
one option for the crypto ipsec df-bit command. If
no global setting is set, the default value is set to
clear.

Table of Contents

Question and Answer IconNeed help?

Do you have a question about the Cisco IOS XR and is the answer not in the manual?

Cisco IOS XR Specifications

General IconGeneral
Operating SystemCisco IOS XR
ArchitectureMicrokernel
High AvailabilityYes
TypeNetwork operating system
Developed byCisco Systems
LicenseProprietary
Programming LanguageC, C++
KernelQNX
Supported PlatformsCisco ASR9000, NCS series
Security FeaturesRole-Based Access Control (RBAC), Secure Boot, Encryption
Management InterfaceCLI, SNMP, NETCONF, RESTCONF
Release Date2004
Target DevicesHigh-end core routers, service provider edge routers, data center interconnect (DCI) routers
Supported HardwareCisco routers and switches
Networking ProtocolsBGP, OSPF, IS-IS, MPLS
Virtualization SupportVirtualization-ready, supports network function virtualization (NFV) and containerization technologies.

Summary

Implementing Certification Authority Interoperability on Cisco IOS XR Software

Prerequisites for Implementing Certification Authority

Lists necessary prerequisites for configuring CA interoperability.

Information About Implementing Certification Authority

Explains CA concepts, standards (IPSec, IKE, PKCS), and authorities.

How to Implement CA Interoperability

Provides step-by-step procedures for CA interoperability configuration.

Implementing Internet Key Exchange Security Protocol on Cisco IOS XR Software

Prerequisites

Lists necessary prerequisites for configuring IKE security protocol.

Information About Implementing IKE Security Protocol Configurations for IPSec Networks

Explains IKE concepts, standards (IKE, IPSec, ISAKMP, Oakley, Skeme), and algorithms.

IKE Policies

Details IKE policy creation, parameter definitions, and peer agreement for negotiation.

Implementing Keychain Management on Cisco IOS XR Software

Restrictions for Implementing Keychain Management

Notes the impact of system clock changes on key validity.

How to Implement Keychain Management

Covers procedures for configuring keychains, key identifiers, and key strings.

Implementing IPSec Network Security on Cisco IOS XR Software

Prerequisites for Implementing IPSec Network Security

Lists necessary prerequisites for configuring IPSec network security.

Information About Implementing IPSec Networks

Explains IPSec concepts like crypto profiles, access lists, and transform sets.

Perfect Forward Secrecy

Ensures IPSec SA keys are not derived from other secrets for enhanced security.

Implementing Secure Shell on Cisco IOS XR Software

Prerequisites to Implementing Secure Shell

Lists required conditions and images for implementing Secure Shell.

Information About Implementing Secure Shell

Explains SSH server, client, SFTP feature, and AAA integration concepts.

How to Implement Secure Shell

Provides step-by-step procedures for configuring SSH server and client.

Implementing Secure Socket Layer on Cisco IOS XR Software

Prerequisites for Implementing Secure Socket Layer

Lists required conditions for SSL implementation, including key generation and CA enrollment.

Information About Implementing Secure Socket Layer

Explains SSL concepts, including the purpose of certification authorities.

How to Implement Secure Socket Layer

Provides procedures for configuring SSL, including key generation and trustpoint setup.

Configuring AAA Services on Cisco IOS XR Software

Prerequisites for Configuring AAA Services

Lists required conditions before configuring AAA services.

Information About Configuring AAA Services

Explains AAA concepts, users, groups, tasks, and administrative models.

How to Configure AAA Services

Procedures for configuring AAA services, including method lists and server communication.

Implementing Management Plane Protection on Cisco IOS XR Software

Restrictions for Implementing Management Plane Protection

Notes that out-of-band configurations for management traffic are not supported.

Information About Implementing Management Plane Protection

Explains management plane protection concepts, interfaces, and control plane.

How to Configure a Device for Management Plane Protection

Provides procedures for configuring MPP to restrict management traffic to specific interfaces.

Related product manuals