Avaya Configuring IP Services Manual de usuario Pagina 375

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 650
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 374
303528-A Rev 00
10-1
Chapter 10
Configuring RIPSO on an IP Interface
IP routers support the Department of Defense (DoD) Revised IP Security Option
(RIPSO), as defined in RFC 1108, on a per-interface basis. While RIPSO RFC
1108 specifies both “basic” and “extended” security options, the Bay Networks
implementation supports only the basic option.
RIPSO is a feature that allows end systems and intermediate systems (routers) to
add labels to or process security labels in IP datagrams that they transmit or
receive on an IP network. The labels specify security classifications (for example,
Top Secret Confidential and Unclassified, in descending order), which can limit
the devices that can access these labeled IP datagrams.
As a labeled IP datagram traverses an IP network, only those systems that have the
proper clearance (that is, whose security classification range covers the
classification specified by the datagram) should accept and forward the datagram.
Any system whose security classification range does not cover the classification
specified by the security label should drop the datagram.
Note:
RIPSO does not include any method of preventing a system that does
not support RIPSO from simply accepting and forwarding labeled datagrams.
Thus, in order for RIPSO to be effective, all systems in a network must support
RIPSO and process IP datagrams as described.
Vista de pagina 374
1 2 ... 370 371 372 373 374 375 376 377 378 379 380 ... 649 650

Comentarios a estos manuales

Sin comentarios