
Configuration Examples
308630-14.00 Rev 00
C-19
Feature Comparison Summary
This section lists the current support status of additional IPsec interoperability
features in BayRS IPsec and Contivity.
Features Supported by Both Platforms
The following features are supported by both BayRS IPsec and Contivity:
• IPsec ESP protocol
• IKE Preshared Keys
• IPsec in tunnel mode
• Perfect forward secrecy (PFS)
• 3DES key generation by Oakley Group 1
• Vendor ID payload
• Delete Payload for IPsec SAs - sending and receiving
• Delete Payload for IKE SAs - receiving only (Contivity also supports sending)
• Static routes
BayRS Features Not Supported by Contivity
Contivity does not support the following BayRS features:
• Frame Relay interface configured as an IPsec gateway.
• Manual IPsec SAs.
• Source and destination address ranges that contain a partial range of a network
as opposed to network only addressing for configuration of accessible
network IP addresses.
• Protocol selector(s) as defined in RFC 2401, “Security Architecture for the
Internet Protocol,” for use as a criterion to allow establishment of an SA.
• PFS support on a per-IPsec tunnel basis. (Contivity uses PFS for all or none of
the sessions [IPsec SAs] over a Branch Office Connection.)
• DES-only and 3DES-only encryption options (without integrity transforms).
• Routing/broadcast traffic in cleartext.
Kommentare zu diesen Handbüchern