
Configuring IPsec Services
1-6
308630-15.1 Rev 00
Figure 1-1 shows how IPsec can protect data communications within an enterprise
and from external hosts.
Figure 1-1. IPsec Environment: Unique SAs Between Routers
IPsec Tunnel Mode
When a security gateway exists at each end of a communication, the security
associations between the gateways are said to be in tunnel mode. The tunnel
metaphor refers to data being visible only at the beginning and end points of the
communication. The IP packets protected by IPsec have regular, “visible” IP
headers, but the packet contents are encrypted, and thus hidden. All BayRS IPsec
communications occur in tunnel mode. Tunnel mode is especially effective for
isolating and protecting enterprise traffic traveling across a public data network, as
shown in Figure 1-1.
IP0088A
Security
associations
(SAs A,B)
Security
associations
(SAs C,A)
Security associations
(SAs B,C)
Server
Router A
Router B Router C
Corporate
headquarters
Host Host
Partner
Branch office
IP security
gateway
IP security
gateway
IP security
gateway
IPsec
services
IPsec
services
IPsec
services
Public
network
Comentários a estes Manuais