Manually Creating An Sa - Brocade Communications Systems SN3000B Administrator's Manual

Brocade web tools administrator's guide - supporting fabric os v7.0.0 (53-1002152-01, march 2012)
Hide thumbs Also See for SN3000B:
Table of Contents

Advertisement

2. Select Add.
3. Enter a name in the Selector Name field.
4. Select the Traffic Flow Direction (in or out).
5. Enter the IP address of the sender in the Source IP Address field.
6. Enter the IP address of the receiver in the Peer IP Address field.
7.
8. The Protocol Name selector allows you to select a specific protocol.
9. Click OK.

Manually creating an SA

Part of manually creating an security association (SA) is to select an IPsec Protection Type. The
choices are discard, bypass, and protect:
To manually create a SA, perform the following steps.
1. Select the SA(Manual) tab.
2. Select Add.
3. Enter a security parameter index number in the SPI (Hexadecimal) field.
4. Enter the IP address of the endpoint that sends the SA in the Source IP Address field.
5. Enter the IP address of the endpoint that receives the SA in the Peer IP Address field.
6. Select the protocol used to carry the transmission using the Protocol Name selector.
7.
8. Select the IPsec Mode.
Web Tools Adminstrator's Guide
53-1002152-01
The Add Selector dialog box displays.
IPsec policies are unidirectional, and must be applied separately to inbound and outbound
flows.
Enter the Transform Name value.
Discard causes data packets to be rejected if there is an invalid pair of source and destination
addresses or invalid port addresses.
Bypass allows a data packet to be transmitted or received without IPsec protection.
Process indicates a data packet is processed using IPsec encryption, IKE authentication, or
both, using encapsulation security protocol (ESP) processing, or authentication header (AH)
protocol processing.
The Add Manual-SA dialog box displays.
The SPI must be manually applied when manually adding an SA.
Select the Traffic Flow Direction (in or out).
IPsec policies are unidirectional, and must be applied separately to inbound and outbound
flows.
-
For the flow from peer to source, select in.
-
For the flow from source to peer select out.
The choices are Transport or Tunnel. Refer to
if you are unfamiliar with Transport and Tunnel modes.
IPsec over management ports
"Transport mode and tunnel mode"
16
on page 201
211

Advertisement

Table of Contents
loading

This manual is also suitable for:

Web tools

Table of Contents