Creating A Security Association - Brocade Communications Systems 8 Administrator's Manual

Supporting fabric os v6.4.0
Hide thumbs Also See for 8:
Table of Contents

Advertisement

Use the following procedure to establish an IKE policy.
1. Select the IKE tab on the IPsec Policies window for Ethernet IPsec.
2. Enter an IKE Policy Name.
3. Enter the IP address of the authentication partner in the Peer IP Address field.
4. Enter the switch's local identifier in the Local Identifier field.
5. Enter the identifier of the remote peer switch in Peer Identifier.
6. Select the Encryption Algorithm option.
7.
8. Select the PRF Algorithm option.
9. Select the DH Group Number option.
10. Select the Authentication Method option.
11. If PSK is chosen as the authentication method, enter the name of the file that holds the
12. If you are using an X.509 certificate for authentication, enter the appropriate file names in the
13. Use the PFS selector to turn Perfect Forward Secrecy (PFS) on or off.

Creating a security association

A security association (SA) describes a set of parameters for providing secure communications
between two endpoints.
Use the following procedure to create a security association.
1. Select the IPsec tab.
2. Select the SA tab.
3. Select Add.
4. Enter a name for the SA in the SA Name field.
5. Select the IPsec Protocol. option.
6. Select the Authentication Algorithm option.
7.
Web Tools Administrator's Guide
53-1001772-01
DRAFT: BROCADE CONFIDENTIAL
The Add IKE Policy dialog box displays.
This is normally the IP address in IPv4 or IPv6 format, but it may also be a DNS name.
This is normally the IP address in IPv4 or IPv6 format, but it may also be a DNS name.
Select the Hash Algorithm option.
pre-shared key in the Pre-Shared Key filename field.
Public Key filename, Private Key filename, and Peer Public Key filename fields in PEM format.
PFS provides additional security by means of a Diffie-Hellman shared secret value. With PFS, if
one key is compromised, previous and subsequent keys are secure because they are not
derived from previous keys.
The IPsec Policies screen displays.
The Add SA dialog box displays.
The choices are ah (for authentication header) and esp (for encapsulated security protocol).
Select the Encryption Algorithm option.
IPsec over management ports
17
237

Advertisement

Table of Contents
loading

Table of Contents