HP ProCurve 7102dl Reference Manual page 923

Secure router sros command line interface
Table of Contents

Advertisement

SROS Command Line Interface Reference Guide
Frame Relay Sub-Interface Config Command Set
Interfaces (Ethernet, Frame Relay, PPP, local)
Static Filter
Static Filter
(in)
(out)
IPSec
IPSec
Decrypt/Discard
Encrypt
NAT/ACP/
Firewall
Router
As shown in the diagram above, data coming into the product is first processed by the static filter
associated with the interface on which the data is received. This access group is a true static filter and is
available for use regardless of whether the firewall is enabled or disabled. Next (if the data is encrypted) it
is sent to the IPSec engine for decryption. The decrypted data is then processed by the stateful inspection
firewall. Therefore, given a terminating VPN tunnel, only unencrypted data is processed by the firewall.
The ACLs for a crypto map on an interface work in reverse logic to the ACLs for a policy-class on an
interface. When specifying the ACLs for a crypto map, the source information is the private local side,
unencrypted source of the data. The destination information will be the far end, unencrypted destination of
the data. However, ACLs for a policy-class work in reverse. The source information for the ACL in a policy
class is the far end. The destination information is the local side.
Usage Examples
The following example applies all crypto maps with the name MyMap to the Frame Relay interface:
ProCurve(config)#interface frame-relay 1.16
ProCurve(config-fr 1.16)#crypto map MyMap
5991-2114
© Copyright 2007 Hewlett-Packard Development Company, L.P.
921

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve secure router 7203dl j8753a j8753a

Table of Contents