What to do if mirror crypto map ACLs are not configured at the peer on a Cisco MDS 9000 Switch?
- JJennifer PooleJul 26, 2025
To resolve this, ensure that mirror crypto map ACLs are configured at the peer for every crypto map ACL configured locally.
What to do if mirror crypto map ACLs are not configured at the peer on a Cisco MDS 9000 Switch?
To resolve this, ensure that mirror crypto map ACLs are configured at the peer for every crypto map ACL configured locally.
What to do if SAs are not refreshed after IKEv2 reconfiguration on a Cisco MDS 9000?
To resolve this, ensure that you have refreshed SAs after any IKEv2 reconfiguration on your Cisco Switch.
Category | Switch |
---|---|
Operating System | Cisco NX-OS |
Ports | Varies by model |
Protocols | Fibre Channel (FC), Fibre Channel over IP (FCIP), iSCSI |
Redundancy | Redundant supervisors, power supplies, and fans |
Management | Cisco Data Center Network Manager (DCNM), CLI, SNMP |
Virtualization Support | VSANs (Virtual SANs) |
Security Features | Fibre Channel Security Protocol (FC-SP) |
Hot Swappable Components | power supplies, fans |
Power Supply Options | AC and DC options available |
Explains the IPsec protocol, its framework, and its support for iSCSI and FCIP.
Lists compatible Cisco MDS 9000 Family hardware for IPsec features.
Details supported IPsec and IKE encryption and authentication algorithms for Windows and Linux.
Provides a list of allowed transform combinations for IKE configuration.
Lists allowed transform combinations for IPsec configuration.
A step-by-step checklist to begin troubleshooting IPsec issues.
Guides users on accessing IPsec and IKE tools within Cisco Fabric Manager.
Provides procedures to troubleshoot IKE and IPsec issues in FCIP configurations.
Lists essential CLI commands for troubleshooting IPsec issues.
Steps to verify IKE configuration compatibility between peers.
How to check IPsec configuration compatibility using the Fabric Manager GUI.
How to check IPsec configuration compatibility using CLI commands.
Steps to ensure Security Policy Databases (SPDs) are compatible between switches.
How to check interface status and IP addresses using Fabric Manager.
How to check interface status and IP addresses using CLI commands.
Steps to verify current peer, mode, and SA index for IPsec.
Troubleshoots issues where Security Associations (SAs) are not re-keying.
Instructions on how to clear specific Security Associations (SAs).
Lists commands to print debug messages for IPsec process issues.
Lists commands to show the internal state of the IKE process.
How to get statistics for IPsec process and interface levels.