
Configuring IPsec Services
3-2
304111-B Rev 00
When you use Site Manager to configure IPsec on an interface for the first time,
configure the menu items displayed in the IPsec Configuration for Interface
window in sequence, starting with the top item, Outbound Policies. You must set
an outbound policy for an IPsec interface before you can link an SA to it.
Creating Policies
You create inbound and outbound policies for an IPsec interface by using a policy
template. A policy template is a policy definition that you create. You can use a
policy template on any IPsec interface.
Each template contains a complete policy specification (criteria, range, and
action) for the interface. This means that each policy itself is completely specified
by the template. You can modify an individual policy to fit the needs of a specific
interface, independent of the template specifications.
Specifying Criteria
The criteria determine the portion of a packet header (IP source address, IP
destination address, protocol number) that is examined by IPsec. For each
criterion, you must specify a range of values. The range represents the actual
criteria values (that is, the IP addresses that are compared to the address of a
packet).
4. Choose
IP, IPSEC, and IKE
.
(Choosing
IPSEC
automatically selects
IP
;
choosing
IKE
automatically selects
IPSEC
and
IP
.)
The IP Configuration window opens.
5. Set the following parameters:
• IP Address
•
Subnetwork Mask
Click on
Help
or see
Configuring IP, ARP,
RIP, and OSPF Services
.
6. Click on
OK
. The IPsec Configuration for Interface
window opens.
Site Manager Procedure
(continued)
You do this System responds
Kommentare zu diesen Handbüchern