Avaya Configuring IPsec Services Bedienungsanleitung Seite 26

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 122
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 25
Configuring IPsec Services
1-8
308630-15.1 Rev 00
Security Gateways
A security gateway establishes SAs between router interfaces configured with
IPsec software. A Nortel Networks router becomes a security gateway when you
enable IPsec on a WAN or Ethernet interface. In this way, a Nortel Networks
router operating as a security gateway provides IPsec services to its internal hosts
and subnetworks.
Hosts or networks on the external side of a security gateway (typically, the overall
Internet) are considered untrusted. Hosts or subnetworks on the internal side of
a security gateway (nodes on your local intranet) are considered trusted because
they are controlled and securely managed by the same network administration
(Figure 1-3
).
Figure 1-3. IPsec Security Gateways and Security Policies
When you add IPsec services to a router to create a security gateway, its internal
hosts and subnetworks can communicate with external hosts that directly operate
IPsec services, or with a remote security gateway that provides IPsec services for
its set of hosts and subnetworks.
Security Policies
When you create an IPsec policy, you control which packets a security gateway
protects, how it handles packets to or from particular addresses or in a particular
protocol, and whether it logs information about these actions.
There are two types of IPsec policies: inbound and outbound. An inbound policy
is used for data packets arriving at a security gateway, and an outbound policy is
used for data packets leaving a security gateway. Each IPsec interface can support
up to 127 inbound and 127 outbound security policies (refer to Figure 1-3
).
IP0078A
Untrusted
network
Local
host
Trusted
network
Outbound policy
Inbound policy (clear text only)
IPsec interface
IPsec interface
Remote
host
Outbound policy
Inbound policy (clear text only)
Security
gateway
Security
gateway
Trusted
network
Seitenansicht 25
1 2 ... 21 22 23 24 25 26 27 28 29 30 31 ... 121 122

Kommentare zu diesen Handbüchern

Keine Kommentare