Configuring IPsec Using FCIP Wizard
Fabric Manager simplifies the configuration of IPsec and IKE by enabling and configuring these features as part of the FCIP configuration using the FCIP Wizard.
To enable IPsec using the FCIP Wizard in Fabric Manager, follow these steps:
- Click the FCIP Wizard icon in the toolbar.
- Choose the switches that act as endpoints for the FCIP link and click Next.
Note These switches must have MPS-14/2 modules installed to configure IPsec on this FCIP link.
- Choose the Gigabit Ethernet ports on each MPS-14/2 module that will form the FCIP link.
- Check the Enforce IPSEC Security check box and set IKE Auth Key .
- Click Next. In the Specify Tunnel Properties dialog, you see the TCP connection characteristics.
- Set the minimum and maximum bandwidth settings and round-trip time for the TCP connections on this FCIP link. Click the Measure button to measure the round-trip time between the Gigabit Ethernet endpoints.
- Check the Enable Write Acceleration check box to enable FCIP write acceleration on this FCIP link.
- Check the Enable Optimum Compression check box to enable IP compression on this FCIP link.
- Click Next to configure the FCIP tunnel parameters.
- Set the Port VSAN for nontrunk/auto and allowed VSAN list for the trunk tunnel. choose a Trunk Mode for this FCIP link.
- Click Finish to create this FCIP link or click Cancel to exit the FCIP Wizard without creating an FCIP link.
To verify that IPsec and IKE are enabled using Fabric Manager, follow these steps:
- Expand Switches > Security and then select IPSEC in the Physical Attributes pane.
- The Control tab is the default. Verify that the switches you want to modify for IPSec are enabled in the Status column.
- Expand Switches > Security and then select IKE in the Physical Attributes pane.
- The Control tab is the default. Verify that the switches you want to modify for IKE are enabled in the Status column.
Copyright © 2002-2007, Cisco Systems, Inc. All rights reserved.