Avaya Configuring Integrated IP Security Manuale Utente

Navigare online o scaricare Manuale Utente per Software Avaya Configuring Integrated IP Security. Avaya Configuring Integrated IP Security User's Manual Manuale Utente

  • Scaricare
  • Aggiungi ai miei manuali
  • Stampa

Sommario

Pagina 1 - Services

Part No. 304111-A Rev 00November 1998BayRS Version 13.10Site Manager Software Version 7.10 Configuring IP Security Services

Pagina 3

304111-A Rev 00 xiTablesTable 2-1. Security Policy Specifications ...2-8Table 2-2. Sec

Pagina 5 - Contents

304111-A Rev 00 xiii PrefaceThis guide describes the Bay Networks® implementation of IP Security and how to configure it on a Bay Networks router.Befo

Pagina 6

Configuring IP Security Servicesxiv 304111-A Rev 00Text ConventionsThis guide uses the following text conventions:angle brackets (< >) Indicate

Pagina 7 - 304111-A

Preface304111-A Rev 00 xv AcronymsThis guide uses the following acronyms:screen text Indicates system output, for example, prompts and system messages

Pagina 8

Configuring IP Security Servicesxvi 304111-A Rev 00Bay Networks Technical PublicationsYou can now print Bay Networks technical manuals and release not

Pagina 9

Preface304111-A Rev 00 xvii How to Get HelpFor product assistance, support contracts, information about educational services, and the telephone number

Pagina 11 - 304111-A Rev 0

304111-A Rev 001-1 Chapter 1OverviewIP Security (IPsec) is the Bay Networks implementation of the Internet Engineering Task Force (IETF) set of standa

Pagina 12

ii 304111-A Rev 004401 Great America Parkway 8 Federal StreetSanta Clara, CA 95054 Billerica, MA 01821Copyright © 1998 Bay Networks, Inc.All rights re

Pagina 13 - Before You Begin

Configuring IP Security Services1-2304111-A Rev 00Supported RoutersBay Networks IP technologies are implemented on BayRS router interfaces supporting

Pagina 14 - Text Conventions

Overview304111-A Rev 001-3 Figure 1-1. IPsec Environment: Unique Security Associations (SAs) Between RoutersIPsec Tunnel ModeWhen there is a security

Pagina 15 - Acronyms

Configuring IP Security Services1-4304111-A Rev 00Security Protocols OverviewIPsec uses two protocols to provide traffic security: • Encapsulating Sec

Pagina 16

Overview304111-A Rev 001-5 IPsec ServicesIPsec services include the confidentiality, integrity, and authentication services for data packets traveling

Pagina 18

304111-A Rev 002-1 Chapter 2Getting Started with IPsecIPsec has three key constructs:• Security gateways• Security policies• Security associations (SA

Pagina 19 - Overview

Configuring IP Security Services2-2304111-A Rev 00Figure 2-1. IPsec Concepts: Security Gateways, Security Policies, and Security Associations (SAs)Sec

Pagina 20 - IPsec Protection

Getting Started with IPsec304111-A Rev 002-3 Figure 2-2. IPsec Security GatewaysWhen you add IPsec services to a security gateway, its internal hosts

Pagina 21 - IPsec Tunnel Mode

Configuring IP Security Services2-4304111-A Rev 00IPsec PoliciesWhen you create an IPsec policy, you control which packets a security gateway protects

Pagina 22 - Security Protocols Overview

Getting Started with IPsec304111-A Rev 002-5 Inbound PoliciesAn inbound policy determines how a security gateway processes clear-text data packets rec

Pagina 23 - IPsec Services

304111-A Rev 00 iiiBay Networks, Inc. Software License AgreementNOTICE: Please carefully read this license agreement before copying or using the acco

Pagina 24

Configuring IP Security Services2-6304111-A Rev 00Figure 2-3. Outbound and Inbound PoliciesSecurity Policy Database (SPD)The criteria (“selectors”) an

Pagina 25 - Getting Started with IPsec

Getting Started with IPsec304111-A Rev 002-7 Security Associations for Bidirectional TrafficA security association provides security services to data

Pagina 26 - Security Gateway

Configuring IP Security Services2-8304111-A Rev 00Summarizing Security Policies and SAsTable 2-1 and Table 2-2 provide a framework for understanding I

Pagina 27 - Security Policies

Getting Started with IPsec304111-A Rev 002-9 Security ProtocolsIPsec uses the following encryption services:• Data Encryption Standard (DES)• Message

Pagina 28 - IPsec Policies

Configuring IP Security Services2-10304111-A Rev 00IPsec ServicesIPsec services consist of confidentiality, integrity, and authentication.Confidential

Pagina 29 - Outbound Policies

Getting Started with IPsec304111-A Rev 002-11 Installing IP Security (IPsec) SoftwareBefore you can enable and use IPsec services, you must create an

Pagina 30 - Security Associations

Configuring IP Security Services2-12304111-A Rev 00To complete the installation process:1.Open the Image Builder directory:• On a PC, the default dire

Pagina 31

304111-A Rev 003-1 Chapter 3Configuring IPsecBefore you configure IPsec, you need to:• Install IP Security (IPsec) software (see “Installing IP Securi

Pagina 32

Configuring IP Security Services3-2304111-A Rev 00Always configure your NPKs locally, not over a network. When you connect a PC or a workstation to a

Pagina 33 - Security Protocols

Configuring IPsec304111-A Rev 003-3 Create and configure a different NPK for each secure router on your network. The NPK should be different on every

Pagina 34

iv 304111-A Rev 00its own data and information and for maintaining adequate procedures apart from the Software to reconstruct lost or altered files,

Pagina 35 - Installation Instructions

Configuring IP Security Services3-4304111-A Rev 00Entering the NPK on the RouterYou enter the NPK into a router locally, using the console port and th

Pagina 36 - 304111-A Rev 00

Configuring IPsec304111-A Rev 003-5 The kset npk command stores your NPK_value in the router NVRAM, and it calculates a hash of this value that it sto

Pagina 37 - Configuring IPsec

Configuring IP Security Services3-6304111-A Rev 00Monitoring NPKsIf the NPK on a router does not match the NPK in the MIB, IPsec services do not work.

Pagina 38 - Node Protection Key (NPK)

Configuring IPsec304111-A Rev 003-7 When you use Site Manager to configure IPsec on an interface for the first time, configure the menu items displaye

Pagina 39 - Generating and Using NPKs

Configuring IP Security Services3-8304111-A Rev 00The corresponding policy actions are:•Drop• Bypass• Protect • Log (a message will be written to the

Pagina 40 - Caution:

Configuring IPsec304111-A Rev 003-9 To create an outbound policy template and policy, complete the following tasks:Site Manager ProcedureYou do this S

Pagina 41 - Changing NPKs

Configuring IP Security Services3-10304111-A Rev 00Policy9. Click on Add Policy. The Create Outbound Policy window opens.10.Enter the policy name in t

Pagina 42 - Enabling IPsec

Configuring IPsec304111-A Rev 003-11 Creating Security AssociationsSecurity associations enable you to provide bidirectional protection for data packe

Pagina 43 - Creating Policies

Configuring IP Security Services3-12304111-A Rev 00To create a protect SA, complete the following tasks: Site Manager ProcedureYou do this System resp

Pagina 44 - Policy Considerations

Configuring IPsec304111-A Rev 003-13 Disabling IPsecTo disable IPsec on all router interfaces configured for it, complete the following tasks. (You ca

Pagina 45

304111-A Rev 00vContents PrefaceBefore You Begin ...

Pagina 47

304111-A Rev 00A-1 Appendix ASite Manager ParametersThis appendix describes the Site Manager parameters for:• Creating a node protection key (NPK)• En

Pagina 48

Configuring IP Security ServicesA-2304111-A Rev 00Enabling IPsec ParametersIPsec Policy ParametersParameter:IP Security EnablePath:Configuration Manag

Pagina 49 - Disabling IPsec

Site Manager Parameters304111-A Rev 00A-3 Security Association ParametersParameter:Policy NamePath: Configuration Manager > Protocols > IP >

Pagina 50

Configuring IP Security ServicesA-4304111-A Rev 00Parameter:Security Parameter IndexPath: Configuration Manager > Protocols > IP > IP Securit

Pagina 51 - Site Manager Parameters

Site Manager Parameters304111-A Rev 00A-5 Parameter:Cipher KeyPath: Configuration Manager > Protocols > IP > IP Security > Security Associ

Pagina 52 - IPsec Policy Parameters

Configuring IP Security ServicesA-6304111-A Rev 00Parameter:Integrity KeyPath: Configuration Manager > Protocols > IP > IP Security > Secu

Pagina 53

304111-A Rev. 00B-1Appendix BDefinitions of k CommandsThis appendix contains definitions of the “k” commands that you use to work in the Technician In

Pagina 55

304111-A Rev 00C-1 Appendix CSecurity Policy and SecurityAssociation ExamplesThis appendix provides examples of outbound and inbound policies and prot

Pagina 56

vi 304111-A Rev 00Security Policy Database (SPD) ...2-6Security Associati

Pagina 57 - Definitions of k Commands

Configuring IP Security ServicesC-2304111-A Rev 00Figure C-1. IPsec Outbound Policies for Routers 1, 2, and 3Example 1: Required Policies on RTR 1 to

Pagina 58

Security Policy and Security Association Examples304111-A Rev 00C-3 Example 2: Required Policies on RTR 2 to Protect Data Between RTR 1 Subnet 192.32.

Pagina 59 - Association Examples

Configuring IP Security ServicesC-4304111-A Rev 00Example 4: Required Outbound Policies on RTR 3 to Protect DataBetween RTR 2 Subnet 192.28.41.0 and R

Pagina 60

Security Policy and Security Association Examples304111-A Rev 00C-5 Example 6: Required Policies on RTR 2 to Allow ESP Traffic to Pass Through and OSP

Pagina 61

Configuring IP Security ServicesC-6304111-A Rev 00Protect and Unprotect Security Associations (SAs)Security associations (SAs) specify which IPsec ser

Pagina 62

Security Policy and Security Association Examples304111-A Rev 00C-7 SA Example 1: Configuring a Single Protect/Unprotect SA PairIn this example, a sin

Pagina 63 - RTR 1 and RTR 2

Configuring IP Security ServicesC-8304111-A Rev 00SA Example 2: Configuring Two Protect/Unprotect SA PairsIn this example, two protect/unprotect SA pa

Pagina 64 - RTR2

Security Policy and Security Association Examples304111-A Rev 00C-9 SA Example 3: Configuring Multiple Protect/Unprotect SA PairsIn this example, mult

Pagina 65

Configuring IP Security ServicesC-10304111-A Rev 00The following two tables show the settings for the protect/unprotect SA pairs between RTR 1 and RTR

Pagina 66

Security Policy and Security Association Examples304111-A Rev 00C-11 The next two tables show the settings for the protect/unprotect SA pairs between

Pagina 67 - RTR4

304111-A Rev 00viiAppendix A Site Manager ParametersNode Protection Key Parameter ...

Pagina 68

Configuring IP Security ServicesC-12304111-A Rev 00The final two tables show the settings for the protect/unprotect SA pairs between RTR 1 and RTR 4 (

Pagina 69

304111-A Rev 00Index-1Numbers40-bit DES key, 2-956-bit DES key, 2-9Aacronyms, xvAH, 1-4auditing, 1-5authentication, 1-5Bbidirectional traffic, 2-7Ccap

Pagina 70

Index-2304111-A Rev 00NNPK, 3-2, A-1NVRAM, 3-5, A-1Ppassword, 3-4policy template, 2-3, 3-7, 3-9PPP, 1-2product support, xviiprotocol, 1-2, 2-4public d

Pagina 72

304111-A Rev 00ixFiguresFigure 1-1. IPsec Environment: Unique Security Associations (SAs)Between Routers ............

Commenti su questo manuale

Nessun commento