
Configuring IP Routers and Interfaces
2-17
Security Label Format
A RIPSO security label is three or more bytes long and specifies the security
classification level and protection authority values for the datagram (Figure 2-6).
Figure 2-6. RIPSO Security Label
The format of the security label is as follows:
• Octet 1 contains a type value of 82
(16)
, identifying the basic security option
format.
• Octet 2 specifies the length of the option (three or more octets, depending on
the presence or absence of authority flags).
• Octet 3 specifies the security classification levels for the datagrams. Valid
security classification levels include
• Octet 4 and beyond identify the protection authorities under whose rules the
datagram is classified at the specified level. (If no authorities have been
identified, then this field is not used.)
The first 7 bits (0 through 6) are flags. Each flag represents a protection
authority. The flags defined for Octet 4 are as follows:
3D
(16)
Top Secret
5A
(16)
Secret
96
(16)
Confidential
AB
(16)
Unclassified
Type Length
Security
Classification
Protection
Authority
IP Datagram...
1 Octet 1 Octet
or More
1 Octet 1 Octet
Kommentare zu diesen Handbüchern