Cisco 1700 Series Specifications Page 37

  • Download
  • Add to my manuals
  • Print
  • Page
    / 258
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 36
2-3
Cisco 1700 Series Router Software Configuration Guide
78-5407-03
Chapter 2 Configuring Security Features
Configuring IP Security
Disabling Hardware Encryption
If your Cisco 1700 series router is equipped with an optional Virtual Private
Network (VPN) module, it provides hardware 3DES encryption by default. If you
wish, you can disable the VPN module and use Cisco IOS software
encryption/decryption instead.
The command that disables the VPN module is as follows:
no crypto engine accelerator
The command is executed in configuration mode. The following is an example of
its use:
Router(config)#no crypto engine accelerator
Warning! all current connections will be torn down.
Do you want to continue? [yes/no]: yes
.
Crypto accelerator in slot 0 disabled
.
switching to IPsec crypto engine
After this command is executed, the following procedure must be performed to
bring up all encryption tunnels appropriately.
Step 1 On all the routers involved, shut down the interfaces that have crypto maps.
Step 2 Enter the following commands on each router.
You may need to repeat these commands until no connections are listed.
Step 3 Bring up the interfaces on all the routers that were shut down in Step 1.
Command Task
clear crypto sa Clear the security associations applied to the
router.
clear crypto isakmp Clear the active IKE connections to the router.
show crypto engine
connections active
List the active connections. In this scenario,
this command verifies that no connections are
active.
Page view 36
1 2 ... 32 33 34 35 36 37 38 39 40 41 42 ... 257 258

Comments to this Manuals

No comments