ADTRAN Stub Routing Spezifikationen Seite 278

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 568
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 277
Crypto Map IKE Command Set Command Reference Guide
278 © 2003 ADTRAN, Inc. 61950860L1-35D
Technology Review
A crypto map entry is a single policy that describes how certain traffic is to be secured. There are two types of
crypto map entries: ipsec-manual and ipsec-ike. Each entry is given an index, which is used to sort the ordered
list.
When a non-secured packet arrives on an interface, the crypto map set associated with that interface is
processed in order. If a crypto map entry matches the non-secured traffic, the traffic is discarded.
When a packet is to be transmitted on an interface, the crypto map set associated with that interface is
processed in order. The first crypto map entry that matches the packet will be used to secure the packet. If a
suitable SA exists, that is used for transmission. Otherwise, IKE is used to establish an SA with the peer. If no
SA exists, and the crypto map entry is respond only, the packet is discarded.
When a secured packet arrives on an interface, its SPI is used to look up an SA. If an SA does not exist, or if
the packet fails any of the security checks (bad authentication, traffic does not match SA selectors, etc.), it is
discarded. If all checks pass, the packet is forwarded normally.
Seitenansicht 277
1 2 ... 273 274 275 276 277 278 279 280 281 282 283 ... 567 568

Kommentare zu diesen Handbüchern

Keine Kommentare