Avaya Configuring Integrated IP Security Bedienungsanleitung Seite 26

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 72
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 25
Configuring IP Security Services
2-2
304111-A Rev 00
Figure 2-1. IPsec Concepts: Security Gateways, Security Policies, and Security
Associations (SAs)
Security Gateway
A Bay Networks router becomes a security gateway when you enable IPsec on a
WAN interface.
A security gateway protects one or more security associations between router
interfaces configured with IPsec software. A Bay Networks router operating as a
security gateway provides IPsec services to its internal hosts and subnetworks.
Hosts or networks on the “external” side of a security gateway are considered
“untrusted.” Hosts or subnetworks on the “internal” side of a security gateway are
considered “trusted” because they are controlled and securely managed by the
same network administration (Figure 2-2).
IP00087A
Inbound Process
Security Associations
Inbound Policies
criteria & action
(bypass, drop, log)
Outbound Policies
criteria & action
(bypass, drop, log
protect)
Outbound Process
Security
Policy
Database
Unprotected SAs
Source/Dest Addr, SPI
Cipher Algo/Key,
Integrity Algo/Key
Protect SAs
Source/Dest Addr, SPI
Cipher Algo/Key,
Integrity Algo/Key
IPsec Gateway WAN Interface
Seitenansicht 25
1 2 ... 21 22 23 24 25 26 27 28 29 30 31 ... 71 72

Kommentare zu diesen Handbüchern

Keine Kommentare