Avaya Configuring IP Security Services Manual do Utilizador Página 1

Consulte online ou descarregue Manual do Utilizador para Software Avaya Configuring IP Security Services. Avaya Configuring IP Security Services User's Manual Manual do Utilizador

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 100
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 0
Configuring IPsec
Services
Part No. 304111-B Rev 00
April 1999
BayRS Version 13.20
Site Manager Software Version 7.20
Vista de página 0
1 2 3 4 5 6 ... 99 100

Resumo do Conteúdo

Página 1 - Services

Configuring IPsec ServicesPart No. 304111-B Rev 00April 1999BayRS Version 13.20Site Manager Software Version 7.20

Página 4

304111-B Rev 00 xiTablesTable 1-1. Security Policy Specifications ...1-14Table 1-2. Manu

Página 6

304111-B Rev 00 xiii PrefaceThis guide describes the Bay Networks® implementation of IP Security and how to configure it on a Bay Networks router.Befo

Página 7 - 304111-B Rev 00 vii

Configuring IPsec Servicesxiv 304111-B Rev 00Text ConventionsThis guide uses the following text conventions:angle brackets (< >) Indicate that y

Página 8

Preface304111-B Rev 00 xv AcronymsThis guide uses the following acronyms:screen text Indicates system output, for example, prompts and system messages

Página 9 - 304111-B Rev 00 ix

Configuring IPsec Servicesxvi 304111-B Rev 00ISAKMP/Oakley Internet Security Association and Key Management Protocol (also known as IKE)IV initializat

Página 10

Preface304111-B Rev 00 xvii Bay Networks Technical PublicationsYou can now print Bay Networks technical manuals and release notes free, directly from

Página 12

304111-B Rev 001-1 Chapter 1Overview of IPsecThis chapter describes the emerging Internet Engineering Task Force standards for security services over

Página 13 - Before You Begin

ii304111-B Rev 00Bay Networks, Inc.4401 Great America ParkwaySanta Clara, CA 95054Copyright © 1999 Bay Networks, Inc.All rights reserved. Printed in t

Página 14 - Text Conventions

Configuring IPsec Services1-2304111-B Rev 00About IPsecIP Security (IPsec) is the Internet Engineering Task Force (IETF) set of emerging standards for

Página 15 - Acronyms

Overview of IPsec304111-B Rev 001-3 IntegrityIntegrity determines whether the data has been altered during transit. The ESP protocol ensures that data

Página 16 - Configuring IPsec Services

Configuring IPsec Services1-4304111-B Rev 00IPsec ProtectionTo configure a router with IPsec, you first configure the router interface as an IP interf

Página 17 - How to Get Help

Overview of IPsec304111-B Rev 001-5 IPsec Tunnel ModeWhen there is a security gateway at each end of a communication, the security associations betwee

Página 18

Configuring IPsec Services1-6304111-B Rev 00Figure 1-2. IPsec Concepts: Security Gateways, Security Policies, and SAsIP00087AInbound processSecurity a

Página 19 - Chapter 1

Overview of IPsec304111-B Rev 001-7 Security GatewaysA security gateway establishes SAs between router interfaces configured with IPsec software. A Ba

Página 20 - IPsec Services

Configuring IPsec Services1-8304111-B Rev 00Security PoliciesWhen you create an IPsec policy, you control which packets a security gateway protects, h

Página 21 - How IPsec Works

Overview of IPsec304111-B Rev 001-9 Inbound PoliciesAn inbound policy determines how a security gateway processes data packets received from an untrus

Página 22 - IPsec Protection

Configuring IPsec Services1-10304111-B Rev 00Policy Criteria SpecificationIPsec software inspects IP packet headers based on the specified criteria to

Página 23 - Elements of IPsec

Overview of IPsec304111-B Rev 001-11 Security AssociationsA security association (SA) is a relationship in which two peers share the necessary informa

Página 24

304111-B Rev 00 iiiBay Networks, Inc. Software License AgreementNOTICE: Please carefully read this license agreement before copying or using the acco

Página 25 - Security Gateways

Configuring IPsec Services1-12304111-B Rev 00Manual Security AssociationsManually configuring security associations is a more cumbersome and labor-int

Página 26 - Security Policies

Overview of IPsec304111-B Rev 001-13 How IKE Negotiates Security AssociationsThe Internet Key Exchange (IKE) protocol automates the process of IPsec S

Página 27 - Outbound Policies

Configuring IPsec Services1-14304111-B Rev 00Summarizing Security Policies and SAsTable 1-1 and Table 1- 2 provide a framework for understanding IPsec

Página 28 - Policy Criteria Specification

Overview of IPsec304111-B Rev 001-15 In Table 1-2, the IP source and destination addresses for the SA are the tunnel end points for the IPsec tunnel t

Página 29 - Security Associations

Configuring IPsec Services1-16304111-B Rev 00• Data Encryption Standard (DES) (56-bit)• 40-bit DES (manual keying only)• Triple DES (3DES) (3DES IPsec

Página 30 - Manual Security Associations

Overview of IPsec304111-B Rev 001-17 Internet Key Exchange (IKE) ProtocolThe Internet Key Exchange (IKE) protocol negotiates and provides private and

Página 31

Configuring IPsec Services1-18304111-B Rev 00Network Requirements for Bay Networks RoutersTo install the IP Security (IPsec) software, the router must

Página 32

304111-B Rev 002-1 Chapter 2Getting Started With IPsecThis chapter describes how to start using IPsec. Before you configure IPsec, you need to:• Upgra

Página 33 - Security Protocols

Configuring IPsec Services2-2304111-B Rev 00Upgrading Router SoftwareTo install the IPsec software, you must be running BayRS Version 13.20 and Site M

Página 34 - Authentication Header

Getting Started With IPsec304111-B Rev 002-3 Completing the Installation ProcessTo complete the installation process:1.Open the Image Builder director

Página 35 - Perfect Forward Secrecy

iv 304111-B Rev 00its own data and information and for maintaining adequate procedures apart from the Software to reconstruct lost or altered files,

Página 36 - Supported WAN Protocols

Configuring IPsec Services2-4304111-B Rev 00Securing Your SiteTo enforce IPsec, carefully restrict unauthorized access to the routers that encrypt dat

Página 37 - Getting Started With IPsec

Getting Started With IPsec304111-B Rev 002-5 Random Number Generator (RNG)The router software uses the secure random number generator (RNG) to generat

Página 38 - Installing the IPsec Software

Configuring IPsec Services2-6304111-B Rev 00To generate an NPK, use a method available at your site to create random 16-digit hexadecimal numbers. Ent

Página 39 - 304111-B Rev 00

Getting Started With IPsec304111-B Rev 002-7 To enter an initial NPK and a seed for encryption:1.If necessary, create a password for the Technician In

Página 40 - Securing Your Configuration

Configuring IPsec Services2-8304111-B Rev 00Changing an NPKTo maintain security, periodically change the NPK on each router.To change an NPK, enter th

Página 41 - Generating NPKs

304111-B Rev 003-1 Chapter 3Configuring IPsecThis chapter includes the following information:Enabling IPsec and IKETo enable IPsec, configure an IP in

Página 42 - Caution:

Configuring IPsec Services3-2304111-B Rev 00When you use Site Manager to configure IPsec on an interface for the first time, configure the menu items

Página 43

Configuring IPsec304111-B Rev 003-3 Specifying an ActionThe action specification in a policy controls how a packet that matches the specified criteria

Página 44 - Monitoring NPKs

Configuring IPsec Services3-4304111-B Rev 00Creating an Outbound PolicyTo create an outbound policy template and policy, complete the following tasks:

Página 45 - Chapter 3

Configuring IPsec304111-B Rev 003-5 Policy9. Click on Add Policy. The Create Outbound Policy window opens.10.Enter the policy name in thePolicy Name f

Página 46 - Creating Policies

304111-B Rev 00 vContents PrefaceBefore You Begin ...

Página 47 - Policy Considerations

Configuring IPsec Services3-6304111-B Rev 00Creating an Inbound PolicyThe process for creating inbound policies is virtually identical to the process

Página 48 - Creating an Outbound Policy

Configuring IPsec304111-B Rev 003-7 Policy9. Click on Add Policy. The Create Inbound Policy window opens.10.Enter the policy name in thePolicy Name fi

Página 49

Configuring IPsec Services3-8304111-B Rev 00Creating Security AssociationsSecurity associations enable you to provide bidirectional protection for dat

Página 50 - Creating an Inbound Policy

Configuring IPsec304111-B Rev 003-9 Creating a Protect SA Automatically Using IKETo use IKE to create automated Protect SAs, complete the following ta

Página 51

Configuring IPsec Services3-10304111-B Rev 00Creating an Unprotect SA Automatically Using IKETo use IKE to create automated Unprotect SAs, complete th

Página 52 - About Manual SA Creation

Configuring IPsec304111-B Rev 003-11 Creating a Protect SA ManuallyTo manually create a Protect SA, complete the following tasks: Site Manager Procedu

Página 53

Configuring IPsec Services3-12304111-B Rev 00Creating an Unprotect SA ManuallyTo manually create an Unprotect SA, complete the following tasks: Site M

Página 54

Configuring IPsec304111-B Rev 003-13 Disabling IPsecTo disable IPsec on all router interfaces configured for it, complete the following tasks. To dis

Página 55

Configuring IPsec Services3-14304111-B Rev 004. Click on Values and select Disable from the dialog box.5. Click on OK to close the dialog. The dialog

Página 56

304111-B Rev 00A-1 Appendix ASite Manager ParametersThis appendix describes the Site Manager parameters for:• Creating a node protection key (NPK)• En

Página 57 - Disabling IPsec

vi 304111-B Rev 00How IKE Negotiates Security Associations ...1-13Security Parameter Index (

Página 58

Configuring IPsec ServicesA-2304111-B Rev 00Enabling IPsec ParametersParameter:IP Security EnablePath:Configuration Manager > Protocols > IP >

Página 59 - Site Manager Parameters

Site Manager Parameters304111-B Rev 00A-3 IPsec Policy ParametersParameter:Policy EnablePath: Configuration Manager > Protocols > IP > IP Sec

Página 60 - Enabling IPsec Parameters

Configuring IPsec ServicesA-4304111-B Rev 00Manual Security Association ParametersParameter:SA Source IP AddressPath: Configuration Manager > Proto

Página 61 - IPsec Policy Parameters

Site Manager Parameters304111-B Rev 00A-5 Parameter:Security Parameter IndexPath: Configuration Manager > Protocols > IP > IP Security > M

Página 62

Configuring IPsec ServicesA-6304111-B Rev 00Parameter:Cipher Key LengthPath: Configuration Manager > Protocols > IP > IP Security > Manual

Página 63

Site Manager Parameters304111-B Rev 00A-7 Parameter:Integrity AlgorithmPath: Configuration Manager > Protocols > IP > IP Security > Manual

Página 64

Configuring IPsec ServicesA-8304111-B Rev 00Parameter:Integrity KeyPath: Configuration Manager > Protocols > IP > IP Security > Manual Sec

Página 65

Site Manager Parameters304111-B Rev 00A-9 Automated Security Association (IKE) ParametersParameter:Pre-Shared KeyPath: Configuration Manager > Prot

Página 67

304111-B Rev 00B-1Appendix BDefinitions of k CommandsThis appendix contains definitions of the “k” commands that you use to work in the Technician Int

Página 68

304111-B Rev 00 viiCreating an Inbound Policy ...3-6Creating Securi

Página 70

304111-B Rev 00C-1 Appendix CConfiguration ExamplesThis appendix provides configuration examples for both automated and manual security associations.

Página 71 - Configuration Examples

Configuring IPsec ServicesC-2304111-B Rev 00Automated SA (IKE) Policy ExamplesAs you review the security policy examples in this section, refer to Fig

Página 72

Configuration Examples304111-B Rev 00C-3 Example 1: Required Policies, Proposals, and SA Destinations on RTR1 and RTR2 to Protect Data Between RTR1 Su

Página 73

Configuring IPsec ServicesC-4304111-B Rev 00Example 3: Required Policies, Proposals, and SA Destinations on RTR1 and RTR4 to Protect Data Between RTR1

Página 74 - RTR4 Subnet 192.32.30.0

Configuration Examples304111-B Rev 00C-5 Manual SA Policy ExamplesAs you review the security policy examples in this section, refer to Figure C-2. All

Página 75 - Manual SA Policy Examples

Configuring IPsec ServicesC-6304111-B Rev 00Example 2: Required Policies on RTR2 to Protect Data Between RTR1 Subnet 192.32.5.0 and RTR2 Subnet 192.28

Página 76

Configuration Examples304111-B Rev 00C-7 Example 3: Required Policies on RTR2 to Protect Data Between RTR2 Subnet 192.28.41.0 and RTR3 Subnet 192.131.

Página 77

Configuring IPsec ServicesC-8304111-B Rev 00Example 6: Required Policies on RTR2 to Allow ESP Traffic to Pass Through and OSPF to Exchange Routing Upd

Página 78 - RTR1 and RTR2

Configuration Examples304111-B Rev 00C-9 Example 7: Required Policies on RTR3 to Protect Data BetweenRTR3 Subnet 192.131.141.0 and RTR1 192.32.5.0Manu

Página 80

Configuring IPsec ServicesC-10304111-B Rev 00SA Example 1: Configuring a Single Protect/Unprotect SA PairIn this example, a single Protect/Unprotect S

Página 81

Configuration Examples304111-B Rev 00C-11 SA Example 2: Configuring Two Protect/Unprotect SA PairsIn this example, two Protect/Unprotect SA pairs are

Página 82 - RTR4

Configuring IPsec ServicesC-12304111-B Rev 00SA Example 3: Configuring Multiple Protect/Unprotect SA PairsIn this example, multiple Protect/Unprotect

Página 83

Configuration Examples304111-B Rev 00C-13 The following two tables show the settings for the Protect/Unprotect SA pairs between RTR1 and RTR2 (refer t

Página 84

Configuring IPsec ServicesC-14304111-B Rev 00The next two tables show the settings for the Protect/Unprotect SA pairs between RTR1 and RTR3 (refer to

Página 85

Configuration Examples304111-B Rev 00C-15 The final two tables show the settings for the Protect/Unprotect SA pairs between RTR1 and RTR4 (refer to Fi

Página 87 - Protocol Numbers

304111-B Rev 00D-1Appendix DProtocol NumbersIPsec policies may include a protocol criterion that references the 1-byte protocol number field in an IP

Página 88

Configuring IPsec ServicesD-2304111-B Rev 00Assigned Internet Protocol Number by NameTable D-1 lists the Internet protocol numbers alphabetically by t

Página 89

Protocol Numbers304111-B Rev 00D-3 14 EMCON n/a98 ENCAP Encapsulation Header50 ESP Encapsulating Security Payload97 ETHERIP Ethernet-within-IP Encapsu

Página 90

304111-B Rev 00 ixFiguresFigure 1-1. IPsec Environment: Unique Security Associations (SAs)Between Routers ...

Página 91

Configuring IPsec ServicesD-4304111-B Rev 0043 IPv6-Route Routing Header for IPv6111 IPX-in-IP IPX in IP28 IRTP Internet Reliable Transaction Protocol

Página 92

Protocol Numbers304111-B Rev 00D-5 27 RDP Reliable Data Protocol46 RSVP Reservation Protocol66 RVD MIT Remote Virtual Disk Protocol64 SAT-EXPAK SATNET

Página 93

Configuring IPsec ServicesD-6304111-B Rev 00Assigned Internet Protocol Numbers by NumberTable D-2 lists the Internet Protocol numbers in order.112 VRR

Página 94

Protocol Numbers304111-B Rev 00D-7 14 EMCON n/a15 XNET Cross Net Debugger16 CHAOS Chaos17 UDP User Datagram Protocol18 MUX Multiplexing19 DCN-MEAS DCN

Página 95

Configuring IPsec ServicesD-8304111-B Rev 0043 IPv6-Route Routing Header for IPv644 IPv6-Frag Fragment Header for IPv645 IDRP Inter-Domain Routing Pro

Página 96

Protocol Numbers304111-B Rev 00D-9 72 CPNX Computer Protocol Network Executive73 CPHB Computer Protocol Heart Beat74 WSN Wang Span Network75 PVP Packe

Página 97

Configuring IPsec ServicesD-10304111-B Rev 00101 IFMP Ipsilon Flow Management Protocol102 PNNI PNNI over IP103 PIM Protocol Independent Multicast104 A

Página 98

304111-B Rev 00Index-1Numbers3DES, 1-16AAccess Node (AN) support, 1-18Access Stack Node (ASN) support, 1-18acronyms, xvAdvanced Remote Node (ARN) supp

Página 99

Index-2304111-B Rev 00IIKEdescription, 1-11enabling, 3-1security associations, 3-8Image Builder, 2-2inbound security policies, 1-3, 1-9initialization

Página 100

304111-B Rev 00Index-3Rrandom number generator (RNG), 2-5random number, generating, 2-6Router Files Manager, 2-2router log, NPK confirmation, 2-8route

Comentários a estes Manuais

Sem comentários