Example: Encrypt Messages Between Two Nodes in a Chassis Cluster
The procedure explains how to optionally configure the control link to encrypt messages exchanged between two nodes in a chassis cluster. When enabled, this configuration secures inter-node communication by using an internally configured IPsec Security Association (SA).
By encrypting the control-link traffic, the chassis cluster ensures that control messages and login-related communications between nodes are protected against unauthorized access, thereby providing a more secure operational environment.
When the internal IPsec SA is configured, IPsec-based rlogin and remote command (rcmd) are enforced so that attackers cannot gain privileged access or observe traffic containing administrator commands and outputs.
You do not need to configure the internal IPsec SA on both nodes because the nodes are synchronized when the configuration is committed.