What to do if mirror crypto map ACLs are not configured at the peer on a Cisco Switch?
- DDawn RushAug 1, 2025
To resolve this, ensure that mirror crypto map ACLs are configured at the peer for every crypto map ACL configured locally.
What to do if mirror crypto map ACLs are not configured at the peer on a Cisco Switch?
To resolve this, ensure that mirror crypto map ACLs are configured at the peer for every crypto map ACL configured locally.
What to do if SAs are not refreshed after IKEv2 reconfiguration on a Cisco Switch?
To resolve this, ensure that you have refreshed SAs after any IKEv2 reconfiguration on your Cisco Switch.
Form Factor | Modular chassis |
---|---|
Port Density | Varies by model |
Supported Protocols | Fibre Channel (FC), Fibre Channel over IP (FCIP), iSCSI |
Management | Cisco Data Center Network Manager (DCNM), CLI, SNMP |
Redundancy | Redundant supervisors, power supplies, and fans |
Security Features | FC-SP |
Model | MDS 9000 Series |
Provides an overview of IPsec protocol and its support in Cisco MDS 9000 Family.
Details hardware compatibility for IPsec features in Cisco MDS 9000 Family.
Lists allowed transform combinations for IKE configuration.
Lists allowed transform combinations for IPsec configuration.
Provides a checklist for initial IPsec troubleshooting steps.
Guides on accessing IPsec and IKE troubleshooting tools in Fabric Manager.
Lists CLI commands for troubleshooting IPsec issues.
Section detailing procedures to troubleshoot IKE and IPsec issues in FCIP configurations.
Illustrates a basic FCIP configuration for encrypted data transfer.
Steps to verify IKE configuration compatibility between peers.
Procedures to verify IPsec config compatibility using Cisco Fabric Manager.
Steps to verify IPsec configuration compatibility using the command-line interface.
How to verify compatibility of Security Policy Databases (SPDs).
Steps to check interface status using Fabric Manager.
Steps to check interface status using the command-line interface.
Procedures to verify security associations (SAs).
Troubleshooting steps when security associations fail to re-key.
How to clear specific security associations (SAs).
Commands for debugging IPsec process messages.
Commands to view the internal state of the IKE process.
Commands to get statistics for IPsec.