Avaya Configuring IP Security Services Manual do Utilizador

Consulte online ou descarregue Manual do Utilizador para Software Avaya Configuring IP Security Services. Avaya Configuring IP Security Services User's Manual Manual do Utilizador

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 100
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 0
Configuring IPsec
Services
Part No. 304111-B Rev 00
April 1999
BayRS Version 13.20
Site Manager Software Version 7.20
Vista de página 0
1 2 3 4 5 6 ... 99 100

Resumo do Conteúdo

Página 1 - Services

Configuring IPsec ServicesPart No. 304111-B Rev 00April 1999BayRS Version 13.20Site Manager Software Version 7.20

Página 4

304111-B Rev 00 xiTablesTable 1-1. Security Policy Specifications ...1-14Table 1-2. Manu

Página 6

304111-B Rev 00 xiii PrefaceThis guide describes the Bay Networks® implementation of IP Security and how to configure it on a Bay Networks router.Befo

Página 7 - 304111-B Rev 00 vii

Configuring IPsec Servicesxiv 304111-B Rev 00Text ConventionsThis guide uses the following text conventions:angle brackets (< >) Indicate that y

Página 8

Preface304111-B Rev 00 xv AcronymsThis guide uses the following acronyms:screen text Indicates system output, for example, prompts and system messages

Página 9 - 304111-B Rev 00 ix

Configuring IPsec Servicesxvi 304111-B Rev 00ISAKMP/Oakley Internet Security Association and Key Management Protocol (also known as IKE)IV initializat

Página 10

Preface304111-B Rev 00 xvii Bay Networks Technical PublicationsYou can now print Bay Networks technical manuals and release notes free, directly from

Página 12

304111-B Rev 001-1 Chapter 1Overview of IPsecThis chapter describes the emerging Internet Engineering Task Force standards for security services over

Página 13 - Before You Begin

ii304111-B Rev 00Bay Networks, Inc.4401 Great America ParkwaySanta Clara, CA 95054Copyright © 1999 Bay Networks, Inc.All rights reserved. Printed in t

Página 14 - Text Conventions

Configuring IPsec Services1-2304111-B Rev 00About IPsecIP Security (IPsec) is the Internet Engineering Task Force (IETF) set of emerging standards for

Página 15 - Acronyms

Overview of IPsec304111-B Rev 001-3 IntegrityIntegrity determines whether the data has been altered during transit. The ESP protocol ensures that data

Página 16 - Configuring IPsec Services

Configuring IPsec Services1-4304111-B Rev 00IPsec ProtectionTo configure a router with IPsec, you first configure the router interface as an IP interf

Página 17 - How to Get Help

Overview of IPsec304111-B Rev 001-5 IPsec Tunnel ModeWhen there is a security gateway at each end of a communication, the security associations betwee

Página 18

Configuring IPsec Services1-6304111-B Rev 00Figure 1-2. IPsec Concepts: Security Gateways, Security Policies, and SAsIP00087AInbound processSecurity a

Página 19 - Chapter 1

Overview of IPsec304111-B Rev 001-7 Security GatewaysA security gateway establishes SAs between router interfaces configured with IPsec software. A Ba

Página 20 - IPsec Services

Configuring IPsec Services1-8304111-B Rev 00Security PoliciesWhen you create an IPsec policy, you control which packets a security gateway protects, h

Página 21 - How IPsec Works

Overview of IPsec304111-B Rev 001-9 Inbound PoliciesAn inbound policy determines how a security gateway processes data packets received from an untrus

Página 22 - IPsec Protection

Configuring IPsec Services1-10304111-B Rev 00Policy Criteria SpecificationIPsec software inspects IP packet headers based on the specified criteria to

Página 23 - Elements of IPsec

Overview of IPsec304111-B Rev 001-11 Security AssociationsA security association (SA) is a relationship in which two peers share the necessary informa

Página 24

304111-B Rev 00 iiiBay Networks, Inc. Software License AgreementNOTICE: Please carefully read this license agreement before copying or using the acco

Página 25 - Security Gateways

Configuring IPsec Services1-12304111-B Rev 00Manual Security AssociationsManually configuring security associations is a more cumbersome and labor-int

Página 26 - Security Policies

Overview of IPsec304111-B Rev 001-13 How IKE Negotiates Security AssociationsThe Internet Key Exchange (IKE) protocol automates the process of IPsec S

Página 27 - Outbound Policies

Configuring IPsec Services1-14304111-B Rev 00Summarizing Security Policies and SAsTable 1-1 and Table 1- 2 provide a framework for understanding IPsec

Página 28 - Policy Criteria Specification

Overview of IPsec304111-B Rev 001-15 In Table 1-2, the IP source and destination addresses for the SA are the tunnel end points for the IPsec tunnel t

Página 29 - Security Associations

Configuring IPsec Services1-16304111-B Rev 00• Data Encryption Standard (DES) (56-bit)• 40-bit DES (manual keying only)• Triple DES (3DES) (3DES IPsec

Página 30 - Manual Security Associations

Overview of IPsec304111-B Rev 001-17 Internet Key Exchange (IKE) ProtocolThe Internet Key Exchange (IKE) protocol negotiates and provides private and

Página 31

Configuring IPsec Services1-18304111-B Rev 00Network Requirements for Bay Networks RoutersTo install the IP Security (IPsec) software, the router must

Página 32

304111-B Rev 002-1 Chapter 2Getting Started With IPsecThis chapter describes how to start using IPsec. Before you configure IPsec, you need to:• Upgra

Página 33 - Security Protocols

Configuring IPsec Services2-2304111-B Rev 00Upgrading Router SoftwareTo install the IPsec software, you must be running BayRS Version 13.20 and Site M

Página 34 - Authentication Header

Getting Started With IPsec304111-B Rev 002-3 Completing the Installation ProcessTo complete the installation process:1.Open the Image Builder director

Página 35 - Perfect Forward Secrecy

iv 304111-B Rev 00its own data and information and for maintaining adequate procedures apart from the Software to reconstruct lost or altered files,

Página 36 - Supported WAN Protocols

Configuring IPsec Services2-4304111-B Rev 00Securing Your SiteTo enforce IPsec, carefully restrict unauthorized access to the routers that encrypt dat

Página 37 - Getting Started With IPsec

Getting Started With IPsec304111-B Rev 002-5 Random Number Generator (RNG)The router software uses the secure random number generator (RNG) to generat

Página 38 - Installing the IPsec Software

Configuring IPsec Services2-6304111-B Rev 00To generate an NPK, use a method available at your site to create random 16-digit hexadecimal numbers. Ent

Página 39 - 304111-B Rev 00

Getting Started With IPsec304111-B Rev 002-7 To enter an initial NPK and a seed for encryption:1.If necessary, create a password for the Technician In

Página 40 - Securing Your Configuration

Configuring IPsec Services2-8304111-B Rev 00Changing an NPKTo maintain security, periodically change the NPK on each router.To change an NPK, enter th

Página 41 - Generating NPKs

304111-B Rev 003-1 Chapter 3Configuring IPsecThis chapter includes the following information:Enabling IPsec and IKETo enable IPsec, configure an IP in

Página 42 - Caution:

Configuring IPsec Services3-2304111-B Rev 00When you use Site Manager to configure IPsec on an interface for the first time, configure the menu items

Página 43

Configuring IPsec304111-B Rev 003-3 Specifying an ActionThe action specification in a policy controls how a packet that matches the specified criteria

Página 44 - Monitoring NPKs

Configuring IPsec Services3-4304111-B Rev 00Creating an Outbound PolicyTo create an outbound policy template and policy, complete the following tasks:

Página 45 - Chapter 3

Configuring IPsec304111-B Rev 003-5 Policy9. Click on Add Policy. The Create Outbound Policy window opens.10.Enter the policy name in thePolicy Name f

Página 46 - Creating Policies

304111-B Rev 00 vContents PrefaceBefore You Begin ...

Página 47 - Policy Considerations

Configuring IPsec Services3-6304111-B Rev 00Creating an Inbound PolicyThe process for creating inbound policies is virtually identical to the process

Página 48 - Creating an Outbound Policy

Configuring IPsec304111-B Rev 003-7 Policy9. Click on Add Policy. The Create Inbound Policy window opens.10.Enter the policy name in thePolicy Name fi

Página 49

Configuring IPsec Services3-8304111-B Rev 00Creating Security AssociationsSecurity associations enable you to provide bidirectional protection for dat

Página 50 - Creating an Inbound Policy

Configuring IPsec304111-B Rev 003-9 Creating a Protect SA Automatically Using IKETo use IKE to create automated Protect SAs, complete the following ta

Página 51

Configuring IPsec Services3-10304111-B Rev 00Creating an Unprotect SA Automatically Using IKETo use IKE to create automated Unprotect SAs, complete th

Página 52 - About Manual SA Creation

Configuring IPsec304111-B Rev 003-11 Creating a Protect SA ManuallyTo manually create a Protect SA, complete the following tasks: Site Manager Procedu

Página 53

Configuring IPsec Services3-12304111-B Rev 00Creating an Unprotect SA ManuallyTo manually create an Unprotect SA, complete the following tasks: Site M

Página 54

Configuring IPsec304111-B Rev 003-13 Disabling IPsecTo disable IPsec on all router interfaces configured for it, complete the following tasks. To dis

Página 55

Configuring IPsec Services3-14304111-B Rev 004. Click on Values and select Disable from the dialog box.5. Click on OK to close the dialog. The dialog

Página 56

304111-B Rev 00A-1 Appendix ASite Manager ParametersThis appendix describes the Site Manager parameters for:• Creating a node protection key (NPK)• En

Página 57 - Disabling IPsec

vi 304111-B Rev 00How IKE Negotiates Security Associations ...1-13Security Parameter Index (

Página 58

Configuring IPsec ServicesA-2304111-B Rev 00Enabling IPsec ParametersParameter:IP Security EnablePath:Configuration Manager > Protocols > IP >

Página 59 - Site Manager Parameters

Site Manager Parameters304111-B Rev 00A-3 IPsec Policy ParametersParameter:Policy EnablePath: Configuration Manager > Protocols > IP > IP Sec

Página 60 - Enabling IPsec Parameters

Configuring IPsec ServicesA-4304111-B Rev 00Manual Security Association ParametersParameter:SA Source IP AddressPath: Configuration Manager > Proto

Página 61 - IPsec Policy Parameters

Site Manager Parameters304111-B Rev 00A-5 Parameter:Security Parameter IndexPath: Configuration Manager > Protocols > IP > IP Security > M

Página 62

Configuring IPsec ServicesA-6304111-B Rev 00Parameter:Cipher Key LengthPath: Configuration Manager > Protocols > IP > IP Security > Manual

Página 63

Site Manager Parameters304111-B Rev 00A-7 Parameter:Integrity AlgorithmPath: Configuration Manager > Protocols > IP > IP Security > Manual

Página 64

Configuring IPsec ServicesA-8304111-B Rev 00Parameter:Integrity KeyPath: Configuration Manager > Protocols > IP > IP Security > Manual Sec

Página 65

Site Manager Parameters304111-B Rev 00A-9 Automated Security Association (IKE) ParametersParameter:Pre-Shared KeyPath: Configuration Manager > Prot

Página 67

304111-B Rev 00B-1Appendix BDefinitions of k CommandsThis appendix contains definitions of the “k” commands that you use to work in the Technician Int

Página 68

304111-B Rev 00 viiCreating an Inbound Policy ...3-6Creating Securi

Página 70

304111-B Rev 00C-1 Appendix CConfiguration ExamplesThis appendix provides configuration examples for both automated and manual security associations.

Página 71 - Configuration Examples

Configuring IPsec ServicesC-2304111-B Rev 00Automated SA (IKE) Policy ExamplesAs you review the security policy examples in this section, refer to Fig

Página 72

Configuration Examples304111-B Rev 00C-3 Example 1: Required Policies, Proposals, and SA Destinations on RTR1 and RTR2 to Protect Data Between RTR1 Su

Página 73

Configuring IPsec ServicesC-4304111-B Rev 00Example 3: Required Policies, Proposals, and SA Destinations on RTR1 and RTR4 to Protect Data Between RTR1

Página 74 - RTR4 Subnet 192.32.30.0

Configuration Examples304111-B Rev 00C-5 Manual SA Policy ExamplesAs you review the security policy examples in this section, refer to Figure C-2. All

Página 75 - Manual SA Policy Examples

Configuring IPsec ServicesC-6304111-B Rev 00Example 2: Required Policies on RTR2 to Protect Data Between RTR1 Subnet 192.32.5.0 and RTR2 Subnet 192.28

Página 76

Configuration Examples304111-B Rev 00C-7 Example 3: Required Policies on RTR2 to Protect Data Between RTR2 Subnet 192.28.41.0 and RTR3 Subnet 192.131.

Página 77

Configuring IPsec ServicesC-8304111-B Rev 00Example 6: Required Policies on RTR2 to Allow ESP Traffic to Pass Through and OSPF to Exchange Routing Upd

Página 78 - RTR1 and RTR2

Configuration Examples304111-B Rev 00C-9 Example 7: Required Policies on RTR3 to Protect Data BetweenRTR3 Subnet 192.131.141.0 and RTR1 192.32.5.0Manu

Página 80

Configuring IPsec ServicesC-10304111-B Rev 00SA Example 1: Configuring a Single Protect/Unprotect SA PairIn this example, a single Protect/Unprotect S

Página 81

Configuration Examples304111-B Rev 00C-11 SA Example 2: Configuring Two Protect/Unprotect SA PairsIn this example, two Protect/Unprotect SA pairs are

Página 82 - RTR4

Configuring IPsec ServicesC-12304111-B Rev 00SA Example 3: Configuring Multiple Protect/Unprotect SA PairsIn this example, multiple Protect/Unprotect

Página 83

Configuration Examples304111-B Rev 00C-13 The following two tables show the settings for the Protect/Unprotect SA pairs between RTR1 and RTR2 (refer t

Página 84

Configuring IPsec ServicesC-14304111-B Rev 00The next two tables show the settings for the Protect/Unprotect SA pairs between RTR1 and RTR3 (refer to

Página 85

Configuration Examples304111-B Rev 00C-15 The final two tables show the settings for the Protect/Unprotect SA pairs between RTR1 and RTR4 (refer to Fi

Página 87 - Protocol Numbers

304111-B Rev 00D-1Appendix DProtocol NumbersIPsec policies may include a protocol criterion that references the 1-byte protocol number field in an IP

Página 88

Configuring IPsec ServicesD-2304111-B Rev 00Assigned Internet Protocol Number by NameTable D-1 lists the Internet protocol numbers alphabetically by t

Página 89

Protocol Numbers304111-B Rev 00D-3 14 EMCON n/a98 ENCAP Encapsulation Header50 ESP Encapsulating Security Payload97 ETHERIP Ethernet-within-IP Encapsu

Página 90

304111-B Rev 00 ixFiguresFigure 1-1. IPsec Environment: Unique Security Associations (SAs)Between Routers ...

Página 91

Configuring IPsec ServicesD-4304111-B Rev 0043 IPv6-Route Routing Header for IPv6111 IPX-in-IP IPX in IP28 IRTP Internet Reliable Transaction Protocol

Página 92

Protocol Numbers304111-B Rev 00D-5 27 RDP Reliable Data Protocol46 RSVP Reservation Protocol66 RVD MIT Remote Virtual Disk Protocol64 SAT-EXPAK SATNET

Página 93

Configuring IPsec ServicesD-6304111-B Rev 00Assigned Internet Protocol Numbers by NumberTable D-2 lists the Internet Protocol numbers in order.112 VRR

Página 94

Protocol Numbers304111-B Rev 00D-7 14 EMCON n/a15 XNET Cross Net Debugger16 CHAOS Chaos17 UDP User Datagram Protocol18 MUX Multiplexing19 DCN-MEAS DCN

Página 95

Configuring IPsec ServicesD-8304111-B Rev 0043 IPv6-Route Routing Header for IPv644 IPv6-Frag Fragment Header for IPv645 IDRP Inter-Domain Routing Pro

Página 96

Protocol Numbers304111-B Rev 00D-9 72 CPNX Computer Protocol Network Executive73 CPHB Computer Protocol Heart Beat74 WSN Wang Span Network75 PVP Packe

Página 97

Configuring IPsec ServicesD-10304111-B Rev 00101 IFMP Ipsilon Flow Management Protocol102 PNNI PNNI over IP103 PIM Protocol Independent Multicast104 A

Página 98

304111-B Rev 00Index-1Numbers3DES, 1-16AAccess Node (AN) support, 1-18Access Stack Node (ASN) support, 1-18acronyms, xvAdvanced Remote Node (ARN) supp

Página 99

Index-2304111-B Rev 00IIKEdescription, 1-11enabling, 3-1security associations, 3-8Image Builder, 2-2inbound security policies, 1-3, 1-9initialization

Página 100

304111-B Rev 00Index-3Rrandom number generator (RNG), 2-5random number, generating, 2-6Router Files Manager, 2-2router log, NPK confirmation, 2-8route

Comentários a estes Manuais

Sem comentários