Download Manual - MTL Instruments Group
Transcript
Configuration is done via two databases. The SPD sets the required IPsec protocols for traffic going from or to configured hosts or networks. The SAD contains the encryption, compression and hash parameters needed to implement the policies required by the SPD for traffic between specific hosts. The AH IPsec protocol is used for authentication. It uses cryptography to detect that the sender has the same hash key the receiver does. It does not provide any secrecy in transit. The ESP protocol is used for encryption. It uses cryptography to hide the contents of traffic in transit from anyone who does not have the secret key it was encrypted with. IPComp is used to compress traffic. It does not provide any secrecy or authenticity guarantees. 12.5.1 Security Policy Database This section is used to create, delete, and modify SPD entries. Caution: Take care when configuring SPD entries. If you do not configure appropriate SAD entriesto go along with them and an SPD entry affects the host you are using to configure the switch, you may find yourself unable to communicate with the switch. To create an SPD entry, click “Add SPD Rule” and set the source, destination, direction, and protocol requirements as appropriate. To save your changes, click Commit Changes. To delete an SPD entry, click the ‘X’ button at the end of the row and click Commit Changes. To modify an SPD entry, change parameters as desired and click Commit Changes. Note: SPD entries will not apply to ICMPv6 Neighbor Discovery traffic. This allows Neighbor Discovery to function together with IKE. (Internally, the system adds high-priority rules bypassing IPsec for Neighbor Advertisement and Neighbor Solicitation packets.) • Source – An address of the form address, address/prefixlen, address/prefixlen[port], or address[port]. This specifies the source host or hosts that this policy will affect. • Destination – An address in one of the same forms accepted by the Source field. This specifies the destination host or hosts that this policy will affect. • Direction – The direction traffic is traveling through the switch. If the switch’s address is specified in the source field, the direction should be Out. If the switch’s address is in the destination field, the direction should be In. • ESP – Whether to require encryption for communication between the specified hosts. • AH – Whether to require authentication for communication between the specified hosts. • IPComp – Whether to require compression for communication between the specified hosts. • Delete – When the button is clicked, this SPD entry will be deleted when changes are committed. 12.5.2 Security Association Database This section is used to create, delete, and modify SAD entries. Caution: Take care when configuring SAD entries. If the keys and SPI values are not the same ontwo communicating hosts and their security policies require encryption or authentication,they will be unable to successfully communicate. You may find yourself unable to communicate with the switch. To create an SAD entry, click “Add Security Association” and set the source, destination, SPI, mode, cipher, hash algorithm, and keys as appropriate. To save your changes, click Commit Changes. To delete an SAD entry, click the ‘X’ button at the end of the row and click Commit Changes. To modify an SAD entry, change parameters as desired and click Commit Changes. • Source – An address of the form address or address[port]. This specifies the source host (and optionally port) for the security association. • Destination – An address of the form address or address[port]. This specifies the destination host (and optionally port) for the security association. 68 INM9200-SW Sept 2013