Troubleshooting port security ························································································································· 147
Configuring IPsec ························································································ 149
Overview ························································································································································ 149
Basic concepts ······································································································································· 149
IPsec tunnel interface ····························································································································· 152
IPsec RRI ··············································································································································· 153
Protocols and standards ························································································································ 154
FIPS compliance ············································································································································ 154
Implementing IPsec ······································································································································· 154
Implementing ACL-based IPsec ···················································································································· 155
Configuring an ACL ································································································································ 156
Configuring an IPsec policy ···················································································································· 160
Enabling invalid SPI recovery ················································································································ 170
Configuring IPsec RRI ···························································································································· 171
Configuring an IPsec profile ··················································································································· 174
IPsec configuration examples ························································································································ 179
Configuring IPsec for RIPng ··················································································································· 193
Configuring IPsec RRI ···························································································································· 196
Configuring IKE ··························································································· 200
Overview ························································································································································ 200
IKE security mechanism ························································································································· 200
IKE operation ········································································································································· 200
IKE functions ·········································································································································· 201
Protocols and standards ························································································································ 202
FIPS compliance ············································································································································ 202
IKE configuration task list ······························································································································· 203
Configuring an IKE proposal ·························································································································· 204
Configuring an IKE peer ································································································································· 205
Setting keepalive timers ································································································································· 207
v
Need help?
Do you have a question about the FlexNetwork MSR Series and is the answer not in the manual?