Creating An Sa Proposal; Adding An Ipsec Transform Policy - Brocade Communications Systems 8 Administrator's Manual

Supporting fabric os v6.4.0
Hide thumbs Also See for 8:
Table of Contents

Advertisement

17
IPsec over management ports
8. Optionally, enter a value in the SPI number field.
9. Click OK.

Creating an SA proposal

An SA proposal is sent from one endpoint to another to negotiate IKE and IPsec policies. An SA
proposal contains one or more security associations (SA). The endpoints must find a match for
each of the following in the SAs sent in the SA proposal:
Use the following procedure to create an SA proposal.
1. Select the SA Proposal tab on the IPsec Policies screen.
2. Select Add.
3. Enter a name in the SA Proposal Name field.
4. Enter the SAs in the SA(s) to use field.
5. Optionally, define SA lifetime parameters.
6. Click OK.

Adding an IPsec transform policy

The IPsec transform policy is the combination of protocols and algorithms applied to a flow of IP
packets. IPsec unidirectional, and policies need to be applied to both inbound and outbound flows.
Part of adding an IPsec transform policy is to select an IPsec Protection Type. The choices are
discard, bypass, and protect:
238
DRAFT: BROCADE CONFIDENTIAL
A Security Parameter Index (SPI) number is automatically assigned, but may be manually
overridden.
The IKE authentication method.
The IKE encryption algorithm.
The IKE hash algorithm.
The Diffie-Hellman group number.
The IKE SA lifetime.
The IP addresses of the endpoints.
The IPsec protocol (AH or ESP).
The IPsec Transform policy.
The Add-SA Proposal dialog box displays.
The SA lifetime may be defined as a time value in seconds (LifeTime in seconds), as the
number of bytes transmitted before the SA is rekeyed (LifeTime in bytes), or both. When both
are used, the SA lifetime is determined by the threshold that is first reached.
Discard causes data packets to be rejected if there is an invalid pair of source and destination
addresses or invalid port addresses.
Bypass allows a data packet to be transmitted or received without IPsec protection.
Web Tools Administrator's Guide
53-1001772-01

Advertisement

Table of Contents
loading

Table of Contents