HP 8/20q HP StorageWorks 8/20q and SN6000 Fibre Channel Switch Enterprise Fabr - Page 106

Security associations

Page 106 highlights

Security associations A security association defines the encryption algorithm and encryption key to apply when called by a security policy. A security policy may call several associations at different times, but each association is related to only one policy. The security association database is the set of all security associations. IP Security configurations can be complex: it is possible to unintentionally configure policies and associations that isolate a switch from all communication. If this happens, you can disable IP security by placing the switch in maintenance mode, and correct the problem through the serial port interface. To create an association, click Add on the Security Association Database side of the IPsec Configuration dialog box. This opens the Create IPsec Security Association dialog box (Figure 59). Table 18 describes the fields in the Create IP Security Association dialog box. Figure 59 Create IP Security Association dialog box Table 18 Create IP Security Association dialog box fields Field Name Description Source Address Description Association name Association description IP address (version 4 or 6) or DNS host name of the host, switch, or gateway from which data originates Destination Address IP address (version 4 or 6) or DNS host name of the host, switch, or gateway receiving data. If you specified an IP address for the Source Address, the Destination Address must use the same IP version format. Protocol Protocol IP security protocol to be used to process data. The protocol can be one of the following: • Encapsulated Security Payload (esp) • Encapsulated Security Payload (esp-old) • Authentication Header (ah) • Authentication Header (ah-old) SPI Security parameters index number 106 Managing Switches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160

106
Managing Switches
Security associations
A security association defines the encryption algorithm and encryption key to apply when called by a
security policy. A security policy may call several associations at different times, but each association is
related to only one policy. The security association database is the set of all security associations. IP
Security configurations can be complex: it is possible to unintentionally configure policies and associations
that isolate a switch from all communication. If this happens, you can disable IP security by placing the
switch in maintenance mode, and correct the problem through the serial port interface.
To create an association, click
Add
on the Security Association Database side of the IPsec Configuration
dialog box. This opens the Create IPsec Security Association dialog box (
Figure 59
).
Table 18
describes
the fields in the Create IP Security Association dialog box.
Figure 59
Create IP Security Association dialog box
Table 18
Create IP Security Association dialog box fields
Field
Description
Name
Association name
Description
Association description
Source Address
IP address (version 4 or 6) or DNS host name of the host, switch, or gateway
from which data originates
Destination Address
IP address (version 4 or 6) or DNS host name of the host, switch, or gateway
receiving data. If you specified an IP address for the Source Address, the
Destination Address must use the same IP version format.
Protocol
Protocol IP security protocol to be used to process data. The protocol can be
one of the following:
Encapsulated Security Payload (esp)
Encapsulated Security Payload (esp-old)
Authentication Header (ah)
Authentication Header (ah-old)
SPI
Security parameters index number