
Configuring IP Services
11-2 117356-A Rev. A
Figure 11-1. Blacker Front-End Network Configuration
BFE devices receive authorization and address translation services from an
Access Control Center residing on the Black network. The ACC makes access
control decisions that determine which hosts are allowed to communicate with
each other. A Key Distribution Center (KDC) residing on the Black network
provides encryption keys and key management services. A BFE device uses these
encryption keys for encrypting traffic between itself and other BFE devices.
The router-to-BFE interface is a modified version of the interface presented in the
1983 DDN X.25 Host Interface Specification. It supports data rates between
1200 b/s and 64 KB/s. In order to support BFE services, the interface must be
configured to support IP with the Revised IP Security Option (RIPSO) enabled.
All IP datagrams transmitted on the interface must contain a RIPSO security label.
The first option in each IP datagram header must be the Basic Security option.
Router
BFE
Router
BFE
Router
BFE
Black network
Red network
Key
X.25 DDN
IP0015A
Comentarios a estos manuales