Avaya Configuring Integrated IP Security Manual do Utilizador

Consulte online ou descarregue Manual do Utilizador para Software Avaya Configuring Integrated IP Security. Avaya Configuring Integrated IP Security User's Manual Manual do Utilizador

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir

Resumo do Conteúdo

Página 1 - Services

Part No. 304111-A Rev 00November 1998BayRS Version 13.10Site Manager Software Version 7.10 Configuring IP Security Services

Página 3

304111-A Rev 00 xiTablesTable 2-1. Security Policy Specifications ...2-8Table 2-2. Sec

Página 5 - Contents

304111-A Rev 00 xiii PrefaceThis guide describes the Bay Networks® implementation of IP Security and how to configure it on a Bay Networks router.Befo

Página 6

Configuring IP Security Servicesxiv 304111-A Rev 00Text ConventionsThis guide uses the following text conventions:angle brackets (< >) Indicate

Página 7 - 304111-A

Preface304111-A Rev 00 xv AcronymsThis guide uses the following acronyms:screen text Indicates system output, for example, prompts and system messages

Página 8

Configuring IP Security Servicesxvi 304111-A Rev 00Bay Networks Technical PublicationsYou can now print Bay Networks technical manuals and release not

Página 9

Preface304111-A Rev 00 xvii How to Get HelpFor product assistance, support contracts, information about educational services, and the telephone number

Página 11 - 304111-A Rev 0

304111-A Rev 001-1 Chapter 1OverviewIP Security (IPsec) is the Bay Networks implementation of the Internet Engineering Task Force (IETF) set of standa

Página 12

ii 304111-A Rev 004401 Great America Parkway 8 Federal StreetSanta Clara, CA 95054 Billerica, MA 01821Copyright © 1998 Bay Networks, Inc.All rights re

Página 13 - Before You Begin

Configuring IP Security Services1-2304111-A Rev 00Supported RoutersBay Networks IP technologies are implemented on BayRS router interfaces supporting

Página 14 - Text Conventions

Overview304111-A Rev 001-3 Figure 1-1. IPsec Environment: Unique Security Associations (SAs) Between RoutersIPsec Tunnel ModeWhen there is a security

Página 15 - Acronyms

Configuring IP Security Services1-4304111-A Rev 00Security Protocols OverviewIPsec uses two protocols to provide traffic security: • Encapsulating Sec

Página 16

Overview304111-A Rev 001-5 IPsec ServicesIPsec services include the confidentiality, integrity, and authentication services for data packets traveling

Página 18

304111-A Rev 002-1 Chapter 2Getting Started with IPsecIPsec has three key constructs:• Security gateways• Security policies• Security associations (SA

Página 19 - Overview

Configuring IP Security Services2-2304111-A Rev 00Figure 2-1. IPsec Concepts: Security Gateways, Security Policies, and Security Associations (SAs)Sec

Página 20 - IPsec Protection

Getting Started with IPsec304111-A Rev 002-3 Figure 2-2. IPsec Security GatewaysWhen you add IPsec services to a security gateway, its internal hosts

Página 21 - IPsec Tunnel Mode

Configuring IP Security Services2-4304111-A Rev 00IPsec PoliciesWhen you create an IPsec policy, you control which packets a security gateway protects

Página 22 - Security Protocols Overview

Getting Started with IPsec304111-A Rev 002-5 Inbound PoliciesAn inbound policy determines how a security gateway processes clear-text data packets rec

Página 23 - IPsec Services

304111-A Rev 00 iiiBay Networks, Inc. Software License AgreementNOTICE: Please carefully read this license agreement before copying or using the acco

Página 24

Configuring IP Security Services2-6304111-A Rev 00Figure 2-3. Outbound and Inbound PoliciesSecurity Policy Database (SPD)The criteria (“selectors”) an

Página 25 - Getting Started with IPsec

Getting Started with IPsec304111-A Rev 002-7 Security Associations for Bidirectional TrafficA security association provides security services to data

Página 26 - Security Gateway

Configuring IP Security Services2-8304111-A Rev 00Summarizing Security Policies and SAsTable 2-1 and Table 2-2 provide a framework for understanding I

Página 27 - Security Policies

Getting Started with IPsec304111-A Rev 002-9 Security ProtocolsIPsec uses the following encryption services:• Data Encryption Standard (DES)• Message

Página 28 - IPsec Policies

Configuring IP Security Services2-10304111-A Rev 00IPsec ServicesIPsec services consist of confidentiality, integrity, and authentication.Confidential

Página 29 - Outbound Policies

Getting Started with IPsec304111-A Rev 002-11 Installing IP Security (IPsec) SoftwareBefore you can enable and use IPsec services, you must create an

Página 30 - Security Associations

Configuring IP Security Services2-12304111-A Rev 00To complete the installation process:1.Open the Image Builder directory:• On a PC, the default dire

Página 31

304111-A Rev 003-1 Chapter 3Configuring IPsecBefore you configure IPsec, you need to:• Install IP Security (IPsec) software (see “Installing IP Securi

Página 32

Configuring IP Security Services3-2304111-A Rev 00Always configure your NPKs locally, not over a network. When you connect a PC or a workstation to a

Página 33 - Security Protocols

Configuring IPsec304111-A Rev 003-3 Create and configure a different NPK for each secure router on your network. The NPK should be different on every

Página 34

iv 304111-A Rev 00its own data and information and for maintaining adequate procedures apart from the Software to reconstruct lost or altered files,

Página 35 - Installation Instructions

Configuring IP Security Services3-4304111-A Rev 00Entering the NPK on the RouterYou enter the NPK into a router locally, using the console port and th

Página 36 - 304111-A Rev 00

Configuring IPsec304111-A Rev 003-5 The kset npk command stores your NPK_value in the router NVRAM, and it calculates a hash of this value that it sto

Página 37 - Configuring IPsec

Configuring IP Security Services3-6304111-A Rev 00Monitoring NPKsIf the NPK on a router does not match the NPK in the MIB, IPsec services do not work.

Página 38 - Node Protection Key (NPK)

Configuring IPsec304111-A Rev 003-7 When you use Site Manager to configure IPsec on an interface for the first time, configure the menu items displaye

Página 39 - Generating and Using NPKs

Configuring IP Security Services3-8304111-A Rev 00The corresponding policy actions are:•Drop• Bypass• Protect • Log (a message will be written to the

Página 40 - Caution:

Configuring IPsec304111-A Rev 003-9 To create an outbound policy template and policy, complete the following tasks:Site Manager ProcedureYou do this S

Página 41 - Changing NPKs

Configuring IP Security Services3-10304111-A Rev 00Policy9. Click on Add Policy. The Create Outbound Policy window opens.10.Enter the policy name in t

Página 42 - Enabling IPsec

Configuring IPsec304111-A Rev 003-11 Creating Security AssociationsSecurity associations enable you to provide bidirectional protection for data packe

Página 43 - Creating Policies

Configuring IP Security Services3-12304111-A Rev 00To create a protect SA, complete the following tasks: Site Manager ProcedureYou do this System resp

Página 44 - Policy Considerations

Configuring IPsec304111-A Rev 003-13 Disabling IPsecTo disable IPsec on all router interfaces configured for it, complete the following tasks. (You ca

Página 45

304111-A Rev 00vContents PrefaceBefore You Begin ...

Página 47

304111-A Rev 00A-1 Appendix ASite Manager ParametersThis appendix describes the Site Manager parameters for:• Creating a node protection key (NPK)• En

Página 48

Configuring IP Security ServicesA-2304111-A Rev 00Enabling IPsec ParametersIPsec Policy ParametersParameter:IP Security EnablePath:Configuration Manag

Página 49 - Disabling IPsec

Site Manager Parameters304111-A Rev 00A-3 Security Association ParametersParameter:Policy NamePath: Configuration Manager > Protocols > IP >

Página 50

Configuring IP Security ServicesA-4304111-A Rev 00Parameter:Security Parameter IndexPath: Configuration Manager > Protocols > IP > IP Securit

Página 51 - Site Manager Parameters

Site Manager Parameters304111-A Rev 00A-5 Parameter:Cipher KeyPath: Configuration Manager > Protocols > IP > IP Security > Security Associ

Página 52 - IPsec Policy Parameters

Configuring IP Security ServicesA-6304111-A Rev 00Parameter:Integrity KeyPath: Configuration Manager > Protocols > IP > IP Security > Secu

Página 53

304111-A Rev. 00B-1Appendix BDefinitions of k CommandsThis appendix contains definitions of the “k” commands that you use to work in the Technician In

Página 55

304111-A Rev 00C-1 Appendix CSecurity Policy and SecurityAssociation ExamplesThis appendix provides examples of outbound and inbound policies and prot

Página 56

vi 304111-A Rev 00Security Policy Database (SPD) ...2-6Security Associati

Página 57 - Definitions of k Commands

Configuring IP Security ServicesC-2304111-A Rev 00Figure C-1. IPsec Outbound Policies for Routers 1, 2, and 3Example 1: Required Policies on RTR 1 to

Página 58

Security Policy and Security Association Examples304111-A Rev 00C-3 Example 2: Required Policies on RTR 2 to Protect Data Between RTR 1 Subnet 192.32.

Página 59 - Association Examples

Configuring IP Security ServicesC-4304111-A Rev 00Example 4: Required Outbound Policies on RTR 3 to Protect DataBetween RTR 2 Subnet 192.28.41.0 and R

Página 60

Security Policy and Security Association Examples304111-A Rev 00C-5 Example 6: Required Policies on RTR 2 to Allow ESP Traffic to Pass Through and OSP

Página 61

Configuring IP Security ServicesC-6304111-A Rev 00Protect and Unprotect Security Associations (SAs)Security associations (SAs) specify which IPsec ser

Página 62

Security Policy and Security Association Examples304111-A Rev 00C-7 SA Example 1: Configuring a Single Protect/Unprotect SA PairIn this example, a sin

Página 63 - RTR 1 and RTR 2

Configuring IP Security ServicesC-8304111-A Rev 00SA Example 2: Configuring Two Protect/Unprotect SA PairsIn this example, two protect/unprotect SA pa

Página 64 - RTR2

Security Policy and Security Association Examples304111-A Rev 00C-9 SA Example 3: Configuring Multiple Protect/Unprotect SA PairsIn this example, mult

Página 65

Configuring IP Security ServicesC-10304111-A Rev 00The following two tables show the settings for the protect/unprotect SA pairs between RTR 1 and RTR

Página 66

Security Policy and Security Association Examples304111-A Rev 00C-11 The next two tables show the settings for the protect/unprotect SA pairs between

Página 67 - RTR4

304111-A Rev 00viiAppendix A Site Manager ParametersNode Protection Key Parameter ...

Página 68

Configuring IP Security ServicesC-12304111-A Rev 00The final two tables show the settings for the protect/unprotect SA pairs between RTR 1 and RTR 4 (

Página 69

304111-A Rev 00Index-1Numbers40-bit DES key, 2-956-bit DES key, 2-9Aacronyms, xvAH, 1-4auditing, 1-5authentication, 1-5Bbidirectional traffic, 2-7Ccap

Página 70

Index-2304111-A Rev 00NNPK, 3-2, A-1NVRAM, 3-5, A-1Ppassword, 3-4policy template, 2-3, 3-7, 3-9PPP, 1-2product support, xviiprotocol, 1-2, 2-4public d

Página 72

304111-A Rev 00ixFiguresFigure 1-1. IPsec Environment: Unique Security Associations (SAs)Between Routers ............

Comentários a estes Manuais

Sem comentários