Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


Cisco IOS IPSec Certificate Authority Support Review

Oct 02,2009 by alperen

image

The steps and related commands are summarized in the following task list:

Task 1 Prepare for IKE and IPSec

  • Step 1–1 Plan for CA support

  • Step 1–2 Determine the IKE (IKE phase one) policies

  • Step 1–3 Determine the IPSec (IKE phase two) policies

  • Step 1–4 Check the current configuration

    show running-configuration

    show isakmp [policy]

    show crypto map

  • Step 1–5 Ensure the network works without encryption

    ping

  • Step 1–6 Ensure access control lists are compatible with IPSec

    show access-lists

Task 2 Configure CA support

Task 3 Configure IKE

Task 4 Configure IPSec

  • Step 4–1 Configure transform set suites

    crypto ipsec transform-set

  • Step 4–2 Configure global IPSec security association lifetimes

    crypto ipsec security-association lifetime

  • Step 4–3 Configure crypto ACLs

    access-list

  • Step 4–4 Configure crypto maps

    crypto map

  • Step 4–5 Apply the crypto maps to the interface

    interface

    crypto map

Task 5 Test and verify IPSec

  • Step 5–1 Display the configured IKE policies

    show crypto isakmp policy

  • Step 5–2 Display the configured transform sets

    show crypto ipsec transform set

  • Step 5–3 Display the current state of the IPSec SAs

    show crypto ipsec sa

  • Step 5–4 Display the configured crypto maps

    show crypto map

  • Step 5–5 Debug IKE events

    debug crypto isakmp

  • Step 5–6 Debug IPSec events

    debug crypto ipsec


298 times read

Related news

» Cisco IOS IPSec for Preshared Keys Review
by alperen posted on Sep 29,2009
» Step 4-4 Display the Configured Crypto Maps
by alperen posted on Sep 27,2009
» CiscoSecure PIX Firewalls Review
by alperen posted on Feb 10,2010
» Task 3 Configure IPSec
by alperen posted on Sep 27,2009
» Step 3-5 Apply the Crypto Maps to the Interface
by alperen posted on Sep 27,2009
Did you enjoy this article?
(total 0 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author