
Configuring IP Services
2-20
Forwarded IP Datagrams
When the router receives an IP datagram that needs forwarding on a RIPSO
interface, the router compares the security classifications and authority values
specified in the security label with those configured on the outbound interface. So,
before forwarding the datagram, the router
• Checks that all RIPSO conditions are met (see above)
• Applies any outbound specific configuration parameters
The router drops any datagrams that do not meet these requirements and generates
an ICMP error message.
Originated IP Datagrams
When the router originates a datagram and the following conditions are true:
• The datagram needs forwarding through a RIPSO interface
• The RIPSO interface requires outbound labels for originated datagrams
the router labels the datagram with the default security label before transmitting it.
Unlabeled IP Datagrams
If the router receives an unlabeled IP datagram from an interface on which RIPSO
is not enabled (or on which labels are not required for inbound datagrams), and
the IP datagram needs forwarding to an interface on which RIPSO is enabled and
labels are required for outbound datagrams, then the router labels the datagram
using either an implicit label or default label as follows:
• If the inbound interface has an implicit label configured, then the router uses it
to label the datagram.
• If the inbound interface does not have an implicit label configured, then the
router labels the datagram with the default label configured for the outbound
interface.
If the interface does not have an implicit or default label configured, then the
datagram is simply dropped.
Comentários a estes Manuais