Adding An Ipsec Transform Policy; Adding An Ipsec Selector - Brocade Communications Systems SN3000B Administrator's Manual

Brocade web tools administrator's guide - supporting fabric os v7.0.0 (53-1002152-01, march 2012)
Hide thumbs Also See for SN3000B:
Table of Contents

Advertisement

16
IPsec over management ports
5. Optionally, define SA lifetime parameters.
6. Click OK.

Adding an IPsec transform policy

The IPsec transform policy is the combination of protocols and algorithms applied to a flow of IP
packets. IPsec unidirectional, and policies need to be applied to both inbound and outbound flows.
Part of adding an IPsec transform policy is to select an IPsec Protection Type. The choices are
discard, bypass, and protect:
To add an IPsec transform policy, perform the following steps.
1. Select the Transforms tab.
2. Select Add.
3. Enter a name in the Transform Name field.
4. Select the IPsec Mode.
5. Enter the SA Proposal name.
6. Select the IPsec Protection Type option.
7.
8. Optional: Enter a local and peer IP address.
9. Click OK.

Adding an IPsec selector

Selectors are used to apply transform policies to an IP flow. Flows are uni-directional. Selectors are
associated with a specific source IP address, a specific peer IP address, and a specific transform.
1. Select the Selectors tab.
210
The SA lifetime may be defined as a time value in seconds (LifeTime in seconds), as the
number of bytes transmitted before the SA is rekeyed (LifeTime in bytes), or both. When both
are used, the SA lifetime is determined by the threshold that is first reached.
Discard causes data packets to be rejected if there is an invalid pair of source and destination
addresses or invalid port addresses.
Bypass allows a data packet to be transmitted or received without IPsec protection.
Process indicates a data packet is processed using IPsec encryption, IKE authentication, or
both, using encapsulation security protocol (ESP) processing, or authentication header (AH)
protocol processing.
The Transforms screen displays.
The Add Transform dialog box displays.
The choices are Transport or Tunnel.
Select the IKE Policy Name option.
IKE policies need to be created before adding a transform policy. If there are no names to
select from, you must create an IKE policy.
The Selectors screen displays.
Web Tools Adminstrator's Guide
53-1002152-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Web tools

Table of Contents