Cisco PIX 525 Especificações Página 240

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 466
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 239
6-28
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 6 Configuring IPSec and Certification Authorities
Viewing IPSec Configuration
Viewing IPSec Configuration
Table 6-2 lists commands you can use to view information about your IPSec configuration.
Ta b l e 6-2 Commands to View IPSec Configuration Information
Command Purpose
show crypto ipsec transform-set View your transform set configuration.
show crypto map [interface interface-name | tag
map-name]
View your crypto map configuration.
show crypto ipsec sa [map map-name | address |
identity] [detail]
View information about IPSec security
associations.
show crypto dynamic-map [tag map-name] View information about dynamic crypto maps.
show crypto ipsec security-association lifetime View global security association lifetime values.
Clearing SAs
Certain configuration changes will only take effect when negotiating subsequent security associations.
If you want the new settings to take immediate effect, clear the existing security associations so that they
will be re-established with the changed configuration. For manually established security associations,
clear and reinitialize the security associations or the changes will never take effect. If the PIX
Firewall
is actively processing IPSec traffic, it is desirable to clear only the portion of the security association
database that would be affected by the configuration changes (that is, clear only the security associations
established by a given crypto map set). Clearing the full security association database should be reserved
for large-scale changes, or when the PIX
Firewall is processing a small number of other IPSec traffic.
Table 6-3 lists commands you can use to clear and reinitialize IPSec security associations.
Ta b l e 6-3 Commands to Clear and Reinitialize IPSec SAs
Command Purpose
crypto map map-name interface interface-name Reinitialize the IPSec run-time security
association database and security policy database.
clear [crypto] ipsec sa
or
clear [crypto] ipsec sa peer ip-address |
peer-name
or
clear [crypto] ipsec sa map map-name
or
clear [crypto] ipsec sa entry destination-address
protocol spi
Clear IPSec security associations.
Note Using the clear [crypto] ipsec sa
command without parameters will clear
out the full security association database,
which will clear out active security
sessions. You may also specify the peer,
map, or entry keywords to clear out only
a subset of the security association
database. For more information, see the
clear [crypto] ipsec sa command within
the Cisco
PIX Firewall Command
Reference.
Vista de página 239
1 2 ... 235 236 237 238 239 240 241 242 243 244 245 ... 465 466

Comentários a estes Manuais

Sem comentários