
Configuring IPsec Services
3-8
308630-14.00 Rev 00
Creating Security Associations
Security associations enable you to provide bidirectional protection for data
packets traveling between two routers. Each SA establishes security for data
passing in a single direction. A pair of SAs (Protect SA and Unprotect SA) are
created, either automatically by IKE or manually by you, for any IPsec policy
configured on a security gateway. Each SA includes security information such as
algorithm and keys.
You should use automated SA creation (IKE) for greater security and decreased
configuration management overhead.
About Automated SA Creation
IKE creates automated SAs, based on the proposals you configure for an IPsec
policy in Site Manager. Each proposal specifies an encryption and/or
authentication transform for the automated SA. You do not need to specify keys
for automated SAs, because IKE creates them dynamically.
You can configure up to four proposals for a policy, in order of preference. IKE
will negotiate an automated SA, based on the first proposal that matches one
configured on the remote security gateway. Both the inbound and the outbound
SAs are created by IKE based on the results of the proposal negotiation.
Comentarios a estos manuales