Cisco PIX 525 Spezifikationen Seite 408

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 604
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 407
23-20
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 23 Configuring IPSec and ISAKMP
Clearing Security Associations
Providing Site-to-Site Redundancy
You can define multiple peers by using crypto maps to provide redundancy. This configuration is useful
for site-to-site VPNs.
If one peer fails, the security appliance establishes a tunnel to the next peer associated with the crypto
map. It sends data to the peer that it has successfully negotiated with, and that peer becomes the "active"
peer. The "active" peer is the peer that the security appliance keeps trying first for follow-on negotiations
until a negotiation fails. At that point the security appliance goes on to the next peer. The security
appliance cycles back to the first peer when all peers associated with the crypto map have failed.
Viewing an IPSec Configuration
Table 23-2 lists commands you can enter to view information about your IPSec configuration.
Clearing Security Associations
Certain configuration changes take effect only when negotiating subsequent security associations. If you
want the new settings to take effect immediately, clear the existing security associations to reestablish
them with the changed configuration. If the security appliance is actively processing IPSec traffic, it is
desirable to clear only the portion of the security association database that the configuration changes
would affect. Reserve clearing the full security association database for large-scale changes, or when the
security appliance is processing a small amount of IPSec traffic.
Table 23-2 Commands to View IPSec Configuration Information
Command Purpose
show running-configuration crypto Displays the entire crypto configuration,
including IPSec, crypto maps, dynamic crypto
maps, and ISAKMP.
show running-config crypto ipsec Displays the complete IPSec configuration.
show running-config crypto isakmp Displays the complete ISAKMP configuration.
show running-config crypto map Displays the complete crypto map configuration.
show running-config crypto dynamic-map Displays the dynamic crypto map configuration.
show all crypto map View all of the configuration parameters,
including those with default values.
Seitenansicht 407
1 2 ... 403 404 405 406 407 408 409 410 411 412 413 ... 603 604

Kommentare zu diesen Handbüchern

Keine Kommentare