Avaya Configuring IPsec Services Manual de usuario Pagina 20

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 122
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 19
Configuring IPsec Services
1-2
308630-15.1 Rev 00
About IPsec
IP Security is the IETF set of emerging standards for security services for
communications over public networks. The standards are documented in the IETF
Requests for Comments (RFCs) 2401 through 2412. Additional RFCs may be
relevant as well.
These standards were developed to ensure secure, private communications for the
remote access, extranet, and intranet virtual private networks (VPNs) used in
enterprise communications. They are the security architecture for the next
generation of IP, called IPv6, but are available for the current IPv4 Internet as
well.
The Nortel Networks implementation of the IETF standards provides network
(layer 3) security services for Ethernet and wide area network (WAN)
communications on Nortel Networks routers.
Configuring IPsec and NAT on One Interface
You can configure both IPsec and unidirectional Network Address Translation
(NAT) on the same router interface. However, the address ranges that you
configure for NAT and in IPsec policy filters cannot overlap.
You configure IPsec using Site Manager. You can configure NAT using either the
BCC or Site Manager. When you configure IPsec and NAT on the same router
interface, IPsec
and NAT
operate independently and do not pass traffic to each
other.
When you configure both IPsec and NAT on the same router interface, NAT takes
precedence over IPsec. For example, if the destination address of an incoming IP
packet does not match any configured NAT public address, then the packet is
processed by IPsec. If the IP packet contains an address that falls within the
configured range of an IPsec policy, then the packet is either protected, bypassed,
or dropped. A packet with a source address not within any IPsec policy range will
be dropped.
Note:
Router interfaces configured for bidirectional NAT do not support
IPsec.
Vista de pagina 19
1 2 ... 15 16 17 18 19 20 21 22 23 24 25 ... 121 122

Comentarios a estos manuales

Sin comentarios