
305753-A Rev 00
5-1
Chapter 5
Connecting the Router to a Blacker Front End
Blacker front end devices provide encryption services for connections over the
unsecured portions of packet-switched networks (Figure 5-1
). Hosts with Blacker
front ends are part of a red virtual network. The packet-switched network that
carries both the data secured by BFE devices and any other unsecured data is
known as the black network.
Figure 5-1. Blacker Front-End Network Configuration
BFE devices receive authorization and address translation services from an access
control center (ACC) residing on the black network. The ACC makes access
control decisions that determine which hosts are allowed to communicate with
each other. A key distribution center (KDC) residing on the black network
provides encryption keys and key management services. A BFE device uses these
encryption keys for encrypting traffic between itself and other BFE devices.
Router
BFE
Router
BFE
Router
BFE
Black network
Red network
Key
X.25 DDN
IP0015A
Kommentare zu diesen Handbüchern