
Configuring IP Services
3-48 114065 Rev. A
Figure 3-8. Blacker Front End Network Configuration
BFE devices receive authorization and address translation services from an
Access Control Center residing on the Black network. The ACC makes access
control decisions that determine which hosts are allowed to communicate with
each other. A Key Distribution Center (KDC) residing on the Black network
provides encryption keys and key management services. A BFE device uses these
encryption keys for encrypting traffic between itself and other BFE devices.
The router-to-BFE interface is a modified version of the interface presented in the
1983 DDN X.25 Host Interface Specification. It supports data rates between 1200
b/s and 64 KB/s. In order to support BFE services, the interface must be
configured to support IP with the Revised IP Security Option (RIPSO) enabled.
All IP datagrams transmitted on the interface must contain a RIPSO security label.
The first option in each IP datagram header must be the Basic Security option.
BFE Addressing
You can enable BFE support on individual IP interfaces. When you enable BFE
support, the router uses the BFE address-resolution algorithm to map IP addresses
to their corresponding X.121 addresses.
BFE IP-to-X.121 address translation differs from standard DDN address
translation. Each physical router-to-BFE connection is identified by a BFE X.121
network address and a BFE IP address. The format of a BFE X.121 address is
Router
BFE
Router
BFE
Router
BFE
Black Network
Red Network
Key
X.25 DDN
IP0015A
Kommentare zu diesen Handbüchern