
Configuration Examples
304111-B Rev 00
C-9
Example 7: Required Policies on RTR3 to Protect Data Between
RTR3 Subnet 192.131.141.0 and RTR1 192.32.5.0
Manual Protect and Unprotect SA Configuration
SAs specify which IPsec services are applied to the data packets traveling between
the security gateways. An individual SA protects data traveling in one direction. A
Protect SA is used to apply IPsec services to outbound traffic; an Unprotect SA is
used to decrypt and/or authenticate incoming data packets.
The examples in this section show how to manually configure both Protect and
Unprotect SAs. Automated SA configuration is achieved using IKE without user
configuration required.
For SA examples 1 and 2, refer to Figure C-3
; for SA example 3, refer to
Figure C-4.
Figure C-3. Single Protect/Unprotect SA Pair
RTR 3 Interface S11
Policy
Outbound
Action
Protect
Criteria
IP source address range: 192.131.141.0 - 192.131.141.255
IP destination address range: 192.32.5.0 - 192.32.5.255
SA
Source: 2.2.2.2
Destination:1.1.1.1 SPI 257
RTR1
RTR2
INET
S31 - 119.68.12.1
189.132.10.1 - S52
Kommentare zu diesen Handbüchern