5–Managing SwitchesConfiguring the Network5-38 59266-01 BSecurity AssociationsA security association defines the encryption algorithm and encryption key toapply when called by a security policy. A security policy may call severalassociations at different times, but each association is related to only one policy.The security association database is the set of all security associations. IPSecurity configurations can be complex: it is possible to unintentionally configurepolicies and associations that isolate a switch from all communication. If thishappens, you can disable IP security by placing the switch in maintenance mode,and correct the problem through the serial port interface.To create an association, click Add on the Security Association Database side ofthe IPsec Configuration dialog box. This opens the Create IPsec SecurityAssociation dialog box (Figure 5-18). Table 5-8 describes the text boxes in theCreate IP Security Association dialog box.Figure 5-18. Create IP Security Association Dialog BoxespRuleLevel Rule level to apply for ESP protection: Default Use RequireTable 5-7. Create IP Security Policy Dialog Box Fields (Continued)Field Description