EasyManua.ls Logo

Alcatel-Lucent OmniSwitch 6850-48 - Discarding Traffic Using Ipsec

Alcatel-Lucent OmniSwitch 6850-48
1162 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
IPsec Overview Configuring IPsec
page 27-10 OmniSwitch AOS Release 6 Network Configuration Guide September 2009
tion is a management tool used to enforce a security policy in the IPsec environment. SA actually speci-
fies encryption and authentication between communicating peers.
Manually configured SAs are unidirectional; bi-directional communication requires at least two SAs, one
for each direction. Manually-configured SAs are specified by a combination of their SPI, source and desti-
nation addresses. However, multiple SAs can be configured for the same source and destination combina-
tion. Such SAs are distinguished by a unique Security Parameter Index (SPI).
SA Keys
Keys are used for encrypting and authenticating the traffic. Key lengths must match what is required by
the encryption or authentication algorithm specified in the SA. Key values may be specified either in hexa-
decimal format or as a string.
Note. The OmniSwitch currently supports manually configured SAs only.
Discarding Traffic using IPsec
In order to discard IP datagrams, a policy is configured in the same manner as an IPsec security policy, the
difference being that the action is set to ‘discard’ instead of ‘ipsec’. A discard policy can prevent IPv6 traf-
fic from traversing the network.

Table of Contents

Other manuals for Alcatel-Lucent OmniSwitch 6850-48

Related product manuals