Avaya Configuring IP Security Services Bedienungsanleitung

Stöbern Sie online oder laden Sie Bedienungsanleitung nach Software Avaya Configuring IP Security Services herunter. Avaya Configuring IP Security Services User's Manual Benutzerhandbuch

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 100
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 0
Configuring IPsec
Services
Part No. 304111-B Rev 00
April 1999
BayRS Version 13.20
Site Manager Software Version 7.20
Seitenansicht 0
1 2 3 4 5 6 ... 99 100

Inhaltsverzeichnis

Seite 1 - Services

Configuring IPsec ServicesPart No. 304111-B Rev 00April 1999BayRS Version 13.20Site Manager Software Version 7.20

Seite 4

304111-B Rev 00 xiTablesTable 1-1. Security Policy Specifications ...1-14Table 1-2. Manu

Seite 6

304111-B Rev 00 xiii PrefaceThis guide describes the Bay Networks® implementation of IP Security and how to configure it on a Bay Networks router.Befo

Seite 7 - 304111-B Rev 00 vii

Configuring IPsec Servicesxiv 304111-B Rev 00Text ConventionsThis guide uses the following text conventions:angle brackets (< >) Indicate that y

Seite 8

Preface304111-B Rev 00 xv AcronymsThis guide uses the following acronyms:screen text Indicates system output, for example, prompts and system messages

Seite 9 - 304111-B Rev 00 ix

Configuring IPsec Servicesxvi 304111-B Rev 00ISAKMP/Oakley Internet Security Association and Key Management Protocol (also known as IKE)IV initializat

Seite 10

Preface304111-B Rev 00 xvii Bay Networks Technical PublicationsYou can now print Bay Networks technical manuals and release notes free, directly from

Seite 12

304111-B Rev 001-1 Chapter 1Overview of IPsecThis chapter describes the emerging Internet Engineering Task Force standards for security services over

Seite 13 - Before You Begin

ii304111-B Rev 00Bay Networks, Inc.4401 Great America ParkwaySanta Clara, CA 95054Copyright © 1999 Bay Networks, Inc.All rights reserved. Printed in t

Seite 14 - Text Conventions

Configuring IPsec Services1-2304111-B Rev 00About IPsecIP Security (IPsec) is the Internet Engineering Task Force (IETF) set of emerging standards for

Seite 15 - Acronyms

Overview of IPsec304111-B Rev 001-3 IntegrityIntegrity determines whether the data has been altered during transit. The ESP protocol ensures that data

Seite 16 - Configuring IPsec Services

Configuring IPsec Services1-4304111-B Rev 00IPsec ProtectionTo configure a router with IPsec, you first configure the router interface as an IP interf

Seite 17 - How to Get Help

Overview of IPsec304111-B Rev 001-5 IPsec Tunnel ModeWhen there is a security gateway at each end of a communication, the security associations betwee

Seite 18

Configuring IPsec Services1-6304111-B Rev 00Figure 1-2. IPsec Concepts: Security Gateways, Security Policies, and SAsIP00087AInbound processSecurity a

Seite 19 - Chapter 1

Overview of IPsec304111-B Rev 001-7 Security GatewaysA security gateway establishes SAs between router interfaces configured with IPsec software. A Ba

Seite 20 - IPsec Services

Configuring IPsec Services1-8304111-B Rev 00Security PoliciesWhen you create an IPsec policy, you control which packets a security gateway protects, h

Seite 21 - How IPsec Works

Overview of IPsec304111-B Rev 001-9 Inbound PoliciesAn inbound policy determines how a security gateway processes data packets received from an untrus

Seite 22 - IPsec Protection

Configuring IPsec Services1-10304111-B Rev 00Policy Criteria SpecificationIPsec software inspects IP packet headers based on the specified criteria to

Seite 23 - Elements of IPsec

Overview of IPsec304111-B Rev 001-11 Security AssociationsA security association (SA) is a relationship in which two peers share the necessary informa

Seite 24

304111-B Rev 00 iiiBay Networks, Inc. Software License AgreementNOTICE: Please carefully read this license agreement before copying or using the acco

Seite 25 - Security Gateways

Configuring IPsec Services1-12304111-B Rev 00Manual Security AssociationsManually configuring security associations is a more cumbersome and labor-int

Seite 26 - Security Policies

Overview of IPsec304111-B Rev 001-13 How IKE Negotiates Security AssociationsThe Internet Key Exchange (IKE) protocol automates the process of IPsec S

Seite 27 - Outbound Policies

Configuring IPsec Services1-14304111-B Rev 00Summarizing Security Policies and SAsTable 1-1 and Table 1- 2 provide a framework for understanding IPsec

Seite 28 - Policy Criteria Specification

Overview of IPsec304111-B Rev 001-15 In Table 1-2, the IP source and destination addresses for the SA are the tunnel end points for the IPsec tunnel t

Seite 29 - Security Associations

Configuring IPsec Services1-16304111-B Rev 00• Data Encryption Standard (DES) (56-bit)• 40-bit DES (manual keying only)• Triple DES (3DES) (3DES IPsec

Seite 30 - Manual Security Associations

Overview of IPsec304111-B Rev 001-17 Internet Key Exchange (IKE) ProtocolThe Internet Key Exchange (IKE) protocol negotiates and provides private and

Seite 31

Configuring IPsec Services1-18304111-B Rev 00Network Requirements for Bay Networks RoutersTo install the IP Security (IPsec) software, the router must

Seite 32

304111-B Rev 002-1 Chapter 2Getting Started With IPsecThis chapter describes how to start using IPsec. Before you configure IPsec, you need to:• Upgra

Seite 33 - Security Protocols

Configuring IPsec Services2-2304111-B Rev 00Upgrading Router SoftwareTo install the IPsec software, you must be running BayRS Version 13.20 and Site M

Seite 34 - Authentication Header

Getting Started With IPsec304111-B Rev 002-3 Completing the Installation ProcessTo complete the installation process:1.Open the Image Builder director

Seite 35 - Perfect Forward Secrecy

iv 304111-B Rev 00its own data and information and for maintaining adequate procedures apart from the Software to reconstruct lost or altered files,

Seite 36 - Supported WAN Protocols

Configuring IPsec Services2-4304111-B Rev 00Securing Your SiteTo enforce IPsec, carefully restrict unauthorized access to the routers that encrypt dat

Seite 37 - Getting Started With IPsec

Getting Started With IPsec304111-B Rev 002-5 Random Number Generator (RNG)The router software uses the secure random number generator (RNG) to generat

Seite 38 - Installing the IPsec Software

Configuring IPsec Services2-6304111-B Rev 00To generate an NPK, use a method available at your site to create random 16-digit hexadecimal numbers. Ent

Seite 39 - 304111-B Rev 00

Getting Started With IPsec304111-B Rev 002-7 To enter an initial NPK and a seed for encryption:1.If necessary, create a password for the Technician In

Seite 40 - Securing Your Configuration

Configuring IPsec Services2-8304111-B Rev 00Changing an NPKTo maintain security, periodically change the NPK on each router.To change an NPK, enter th

Seite 41 - Generating NPKs

304111-B Rev 003-1 Chapter 3Configuring IPsecThis chapter includes the following information:Enabling IPsec and IKETo enable IPsec, configure an IP in

Seite 42 - Caution:

Configuring IPsec Services3-2304111-B Rev 00When you use Site Manager to configure IPsec on an interface for the first time, configure the menu items

Seite 43

Configuring IPsec304111-B Rev 003-3 Specifying an ActionThe action specification in a policy controls how a packet that matches the specified criteria

Seite 44 - Monitoring NPKs

Configuring IPsec Services3-4304111-B Rev 00Creating an Outbound PolicyTo create an outbound policy template and policy, complete the following tasks:

Seite 45 - Chapter 3

Configuring IPsec304111-B Rev 003-5 Policy9. Click on Add Policy. The Create Outbound Policy window opens.10.Enter the policy name in thePolicy Name f

Seite 46 - Creating Policies

304111-B Rev 00 vContents PrefaceBefore You Begin ...

Seite 47 - Policy Considerations

Configuring IPsec Services3-6304111-B Rev 00Creating an Inbound PolicyThe process for creating inbound policies is virtually identical to the process

Seite 48 - Creating an Outbound Policy

Configuring IPsec304111-B Rev 003-7 Policy9. Click on Add Policy. The Create Inbound Policy window opens.10.Enter the policy name in thePolicy Name fi

Seite 49

Configuring IPsec Services3-8304111-B Rev 00Creating Security AssociationsSecurity associations enable you to provide bidirectional protection for dat

Seite 50 - Creating an Inbound Policy

Configuring IPsec304111-B Rev 003-9 Creating a Protect SA Automatically Using IKETo use IKE to create automated Protect SAs, complete the following ta

Seite 51

Configuring IPsec Services3-10304111-B Rev 00Creating an Unprotect SA Automatically Using IKETo use IKE to create automated Unprotect SAs, complete th

Seite 52 - About Manual SA Creation

Configuring IPsec304111-B Rev 003-11 Creating a Protect SA ManuallyTo manually create a Protect SA, complete the following tasks: Site Manager Procedu

Seite 53

Configuring IPsec Services3-12304111-B Rev 00Creating an Unprotect SA ManuallyTo manually create an Unprotect SA, complete the following tasks: Site M

Seite 54

Configuring IPsec304111-B Rev 003-13 Disabling IPsecTo disable IPsec on all router interfaces configured for it, complete the following tasks. To dis

Seite 55

Configuring IPsec Services3-14304111-B Rev 004. Click on Values and select Disable from the dialog box.5. Click on OK to close the dialog. The dialog

Seite 56

304111-B Rev 00A-1 Appendix ASite Manager ParametersThis appendix describes the Site Manager parameters for:• Creating a node protection key (NPK)• En

Seite 57 - Disabling IPsec

vi 304111-B Rev 00How IKE Negotiates Security Associations ...1-13Security Parameter Index (

Seite 58

Configuring IPsec ServicesA-2304111-B Rev 00Enabling IPsec ParametersParameter:IP Security EnablePath:Configuration Manager > Protocols > IP >

Seite 59 - Site Manager Parameters

Site Manager Parameters304111-B Rev 00A-3 IPsec Policy ParametersParameter:Policy EnablePath: Configuration Manager > Protocols > IP > IP Sec

Seite 60 - Enabling IPsec Parameters

Configuring IPsec ServicesA-4304111-B Rev 00Manual Security Association ParametersParameter:SA Source IP AddressPath: Configuration Manager > Proto

Seite 61 - IPsec Policy Parameters

Site Manager Parameters304111-B Rev 00A-5 Parameter:Security Parameter IndexPath: Configuration Manager > Protocols > IP > IP Security > M

Seite 62

Configuring IPsec ServicesA-6304111-B Rev 00Parameter:Cipher Key LengthPath: Configuration Manager > Protocols > IP > IP Security > Manual

Seite 63

Site Manager Parameters304111-B Rev 00A-7 Parameter:Integrity AlgorithmPath: Configuration Manager > Protocols > IP > IP Security > Manual

Seite 64

Configuring IPsec ServicesA-8304111-B Rev 00Parameter:Integrity KeyPath: Configuration Manager > Protocols > IP > IP Security > Manual Sec

Seite 65

Site Manager Parameters304111-B Rev 00A-9 Automated Security Association (IKE) ParametersParameter:Pre-Shared KeyPath: Configuration Manager > Prot

Seite 67

304111-B Rev 00B-1Appendix BDefinitions of k CommandsThis appendix contains definitions of the “k” commands that you use to work in the Technician Int

Seite 68

304111-B Rev 00 viiCreating an Inbound Policy ...3-6Creating Securi

Seite 70

304111-B Rev 00C-1 Appendix CConfiguration ExamplesThis appendix provides configuration examples for both automated and manual security associations.

Seite 71 - Configuration Examples

Configuring IPsec ServicesC-2304111-B Rev 00Automated SA (IKE) Policy ExamplesAs you review the security policy examples in this section, refer to Fig

Seite 72

Configuration Examples304111-B Rev 00C-3 Example 1: Required Policies, Proposals, and SA Destinations on RTR1 and RTR2 to Protect Data Between RTR1 Su

Seite 73

Configuring IPsec ServicesC-4304111-B Rev 00Example 3: Required Policies, Proposals, and SA Destinations on RTR1 and RTR4 to Protect Data Between RTR1

Seite 74 - RTR4 Subnet 192.32.30.0

Configuration Examples304111-B Rev 00C-5 Manual SA Policy ExamplesAs you review the security policy examples in this section, refer to Figure C-2. All

Seite 75 - Manual SA Policy Examples

Configuring IPsec ServicesC-6304111-B Rev 00Example 2: Required Policies on RTR2 to Protect Data Between RTR1 Subnet 192.32.5.0 and RTR2 Subnet 192.28

Seite 76

Configuration Examples304111-B Rev 00C-7 Example 3: Required Policies on RTR2 to Protect Data Between RTR2 Subnet 192.28.41.0 and RTR3 Subnet 192.131.

Seite 77

Configuring IPsec ServicesC-8304111-B Rev 00Example 6: Required Policies on RTR2 to Allow ESP Traffic to Pass Through and OSPF to Exchange Routing Upd

Seite 78 - RTR1 and RTR2

Configuration Examples304111-B Rev 00C-9 Example 7: Required Policies on RTR3 to Protect Data BetweenRTR3 Subnet 192.131.141.0 and RTR1 192.32.5.0Manu

Seite 80

Configuring IPsec ServicesC-10304111-B Rev 00SA Example 1: Configuring a Single Protect/Unprotect SA PairIn this example, a single Protect/Unprotect S

Seite 81

Configuration Examples304111-B Rev 00C-11 SA Example 2: Configuring Two Protect/Unprotect SA PairsIn this example, two Protect/Unprotect SA pairs are

Seite 82 - RTR4

Configuring IPsec ServicesC-12304111-B Rev 00SA Example 3: Configuring Multiple Protect/Unprotect SA PairsIn this example, multiple Protect/Unprotect

Seite 83

Configuration Examples304111-B Rev 00C-13 The following two tables show the settings for the Protect/Unprotect SA pairs between RTR1 and RTR2 (refer t

Seite 84

Configuring IPsec ServicesC-14304111-B Rev 00The next two tables show the settings for the Protect/Unprotect SA pairs between RTR1 and RTR3 (refer to

Seite 85

Configuration Examples304111-B Rev 00C-15 The final two tables show the settings for the Protect/Unprotect SA pairs between RTR1 and RTR4 (refer to Fi

Seite 87 - Protocol Numbers

304111-B Rev 00D-1Appendix DProtocol NumbersIPsec policies may include a protocol criterion that references the 1-byte protocol number field in an IP

Seite 88

Configuring IPsec ServicesD-2304111-B Rev 00Assigned Internet Protocol Number by NameTable D-1 lists the Internet protocol numbers alphabetically by t

Seite 89

Protocol Numbers304111-B Rev 00D-3 14 EMCON n/a98 ENCAP Encapsulation Header50 ESP Encapsulating Security Payload97 ETHERIP Ethernet-within-IP Encapsu

Seite 90

304111-B Rev 00 ixFiguresFigure 1-1. IPsec Environment: Unique Security Associations (SAs)Between Routers ...

Seite 91

Configuring IPsec ServicesD-4304111-B Rev 0043 IPv6-Route Routing Header for IPv6111 IPX-in-IP IPX in IP28 IRTP Internet Reliable Transaction Protocol

Seite 92

Protocol Numbers304111-B Rev 00D-5 27 RDP Reliable Data Protocol46 RSVP Reservation Protocol66 RVD MIT Remote Virtual Disk Protocol64 SAT-EXPAK SATNET

Seite 93

Configuring IPsec ServicesD-6304111-B Rev 00Assigned Internet Protocol Numbers by NumberTable D-2 lists the Internet Protocol numbers in order.112 VRR

Seite 94

Protocol Numbers304111-B Rev 00D-7 14 EMCON n/a15 XNET Cross Net Debugger16 CHAOS Chaos17 UDP User Datagram Protocol18 MUX Multiplexing19 DCN-MEAS DCN

Seite 95

Configuring IPsec ServicesD-8304111-B Rev 0043 IPv6-Route Routing Header for IPv644 IPv6-Frag Fragment Header for IPv645 IDRP Inter-Domain Routing Pro

Seite 96

Protocol Numbers304111-B Rev 00D-9 72 CPNX Computer Protocol Network Executive73 CPHB Computer Protocol Heart Beat74 WSN Wang Span Network75 PVP Packe

Seite 97

Configuring IPsec ServicesD-10304111-B Rev 00101 IFMP Ipsilon Flow Management Protocol102 PNNI PNNI over IP103 PIM Protocol Independent Multicast104 A

Seite 98

304111-B Rev 00Index-1Numbers3DES, 1-16AAccess Node (AN) support, 1-18Access Stack Node (ASN) support, 1-18acronyms, xvAdvanced Remote Node (ARN) supp

Seite 99

Index-2304111-B Rev 00IIKEdescription, 1-11enabling, 3-1security associations, 3-8Image Builder, 2-2inbound security policies, 1-3, 1-9initialization

Seite 100

304111-B Rev 00Index-3Rrandom number generator (RNG), 2-5random number, generating, 2-6Router Files Manager, 2-2router log, NPK confirmation, 2-8route

Kommentare zu diesen Handbüchern

Keine Kommentare