
Configuring IP Services
3-38 114065 Rev. A
RIPSO is a feature that allows end systems and intermediate systems (routers) to
add labels to or process security labels in IP datagrams that they transmit or
receive on an IP network. The labels specify security classifications (for example,
Top Secret Confidential, and Unclassified, in descending order), which can be
used to limit the devices that can access these labeled IP datagrams.
As a labeled IP datagram traverses an IP network, only those systems that have the
proper clearance (that is, whose security classification range covers the
classification specified by the datagram) should accept and forward the datagram.
Any system whose security classification range does not cover the classification
specified by the security label should drop the datagram.
By default, RIPSO is disabled on IP interfaces. You can use Site Manager to
enable RIPSO on an IP interface and specify the following:
• A range of acceptable security levels for IP datagrams the interface receives
and transmits
• A set of required and allowed authority values for IP datagrams the interface
receives and transmits
• Whether inbound datagrams received on this interface require security labels
• Whether outbound datagrams transmitted on this interface (either forwarded
or originated by the router) require security labels
• Whether datagrams received or transmitted on this interface should have their
labels stripped
You also specify whether the router creates the following types of labels:
• An implicit label, which the router uses to label unlabeled inbound datagrams,
when required
• A default label, which the router uses to label unlabeled outbound datagrams,
when required
• An error label, which the router uses to label ICMP error messages associated
with processing security options
Note: RIPSO does not include any method of preventing a system that does
not support RIPSO from simply accepting and forwarding labeled datagrams.
Thus, in order for RIPSO to be effective, all systems in a network must support
RIPSO and process IP datagrams as described.
Comentarios a estos manuales