informatique:cisco:ipsec
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revisionNext revisionBoth sides next revision | ||
informatique:cisco:ipsec [2011/07/13 14:55] – ajout de liens pteu | informatique:cisco:ipsec [2013/04/10 10:02] – [Définition de la crypto map] pteu | ||
---|---|---|---|
Line 125: | Line 125: | ||
match address 101 | match address 101 | ||
set transform-set Aes_sha | set transform-set Aes_sha | ||
+ | set pfs group2 | ||
</ | </ | ||
Line 264: | Line 265: | ||
| | ||
+ | |||
+ | ====Accélération matérielle==== | ||
+ | |||
+ | Sur certains châssis on peut utiliser des modules d' | ||
+ | <code bash> | ||
+ | ! prise en charge de la crypto par la carte SPA | ||
+ | crypto engine gre vpnblade | ||
+ | ! | ||
+ | ! prise en charge par la carte supervisor | ||
+ | crypto engine gre supervisor | ||
+ | </ | ||
=====Vérifs===== | =====Vérifs===== | ||
Line 273: | Line 285: | ||
show crypto engine connection active | show crypto engine connection active | ||
- | ====Etat des tunnels==== | + | ====État des tunnels==== |
- | < | + | < |
- | sh crypto session | + | show crypto session |
Crypto session current status | Crypto session current status | ||
Line 302: | Line 314: | ||
Plus de détails : on précise l' | Plus de détails : on précise l' | ||
<code bash> | <code bash> | ||
- | Router1#sh crypto ipsec sa peer 10.1.1.1 | + | Router1#show crypto ipsec sa peer 10.1.1.1 |
interface: Vlan2784 | interface: Vlan2784 | ||
Line 351: | Line 363: | ||
| | ||
+ | </ | ||
+ | |||
+ | Autres commandes, en vrac : | ||
+ | <code bash> | ||
+ | show crypto engine accel stat slot x/y detail et/ou | ||
+ | show crypto ipsec sa | ||
+ | ! | ||
+ | show crypto ace polo detail | ||
+ | show int tunnel351 stats | ||
+ | show crypto vlan | ||
+ | show crypto engine accelerator statistic all | ||
+ | show ip int tu351 | ||
+ | ! | ||
+ | clear crypto engine accelerator counter all | ||
+ | clear crypto session local 10.4.101.97 | ||
</ | </ | ||
Line 376: | Line 403: | ||
* [[http:// | * [[http:// | ||
- | En vrac, des liens destiner | + | En vrac, des liens destinés |
* [[http:// | * [[http:// | ||
* [[http:// | * [[http:// |
informatique/cisco/ipsec.txt · Last modified: 2013/10/14 20:44 by 127.0.0.1