HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 261

implementing ACL-based IPsec, IPv4 source guard

Page 261 highlights

configuring IKE-based tunnel for IPv4 packets, 218 configuring manual policy, 206 configuring manual tunnel for IPv4 packets, 216 configuring transform set, 204 displaying, 215 enabling ACL checking for de-encapsulated IPsec packets, 212 enabling logging of IPsec packets, 214 enabling QoS pre-classify, 213 encapsulation modes, 198 encryption, 200 IKE, 222 IKE configuration, 224 IKE negotiation failure (no proposal or keychain referenced correctly), 236 IKE negotiation failure troubleshooting (no proposal match), 235 IKE negotiation process, 222 IKE security mechanism, 223 IKE troubleshooting, 235 implementation, 201 implementing ACL-based IPsec, 202 keywords in ACL rules, 203 maintaining, 215 mirror image ACLs, 204 protocols and standards, 202 SA, 200 SA negotiation failure (invalid identity info), 237 SA negotiation failure (no transform set match), 236 security protocols, 198 tunnel establishment, 202 IPsec policy applying, 211 binding to source interface, 213 configuration (IKE mode), 207 configuration (manual mode), 206 IPsec policy template configuring IKE-based IPsec policy, 209 IPsec transform set configuration, 204 IPsec tunnel configuring for IPv4 packets (IKE mode), 218 configuring for IPv4 packets (manual mode), 216 IPv4 configuring IKE-based IPsec tunnel, 218 configuring manual IPsec tunnel, 216 IPv4 source guard configuration, 161, 162, 162 displaying, 165 dynamic binding entries, 162 dynamic configuration with DHCP relay, 169 dynamic configuration with DHCP snooping, 167 maintaining, 165 on interface, 162 static binding entries, 161 static configuration, 165 static entry on interface, 163 IPv6 source guard configuration, 161, 162, 164 displaying, 165 maintaining, 165 on interface, 164 static binding entries, 161 static configuration, 170 static entry on interface, 164 ISAKMP, 222, See also IKE ISP AAA implementation, 11 AAA ISP domain accounting methods configuration, 43 AAA ISP domain authentication methods configuration, 41 AAA ISP domain authorization methods configuration, 42 AAA ISP domain creation, 40 AAA ISP domain methods configuration, 40 AAA ISP domain status configuration, 41 K key modulus creating local key pair, 116 key pair security SSH DSA host key pair, 127 security SSH RSA host key pair, 127 security SSH RSA server key pair, 127 L LAN 802.1X overview, 59 252

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

252
configuring IKE-based tunnel for IPv4
packets,
218
configuring manual policy,
206
configuring manual tunnel for IPv4 packets,
216
configuring transform set,
204
displaying,
215
enabling ACL checking for de-encapsulated
IPsec packets,
212
enabling logging of IPsec packets,
214
enabling QoS pre-classify,
213
encapsulation modes,
198
encryption,
200
IKE,
222
IKE configuration,
224
IKE negotiation failure (no proposal or keychain
referenced correctly),
236
IKE negotiation failure troubleshooting (no
proposal match),
235
IKE negotiation process,
222
IKE security mechanism,
223
IKE troubleshooting,
235
implementation,
201
implementing ACL-based IPsec,
202
keywords in ACL rules,
203
maintaining,
215
mirror image ACLs,
204
protocols and standards,
202
SA,
200
SA negotiation failure (invalid identity info),
237
SA negotiation failure (no transform set
match),
236
security protocols,
198
tunnel establishment,
202
IPsec policy
applying,
211
binding to source interface,
213
configuration (IKE mode),
207
configuration (manual mode),
206
IPsec policy template
configuring IKE-based IPsec policy,
209
IPsec transform set
configuration,
204
IPsec tunnel
configuring for IPv4 packets (IKE mode),
218
configuring for IPv4 packets (manual
mode),
216
IPv4
configuring IKE-based IPsec tunnel,
218
configuring manual IPsec tunnel,
216
IPv4 source guard
configuration,
161
,
162
,
162
displaying,
165
dynamic binding entries,
162
dynamic configuration with DHCP relay,
169
dynamic configuration with DHCP snooping,
167
maintaining,
165
on interface,
162
static binding entries,
161
static configuration,
165
static entry on interface,
163
IPv6 source guard
configuration,
161
,
162
,
164
displaying,
165
maintaining,
165
on interface,
164
static binding entries,
161
static configuration,
170
static entry on interface,
164
ISAKMP,
222
,
See also
IKE
ISP
AAA implementation,
11
AAA ISP domain accounting methods
configuration,
43
AAA ISP domain authentication methods
configuration,
41
AAA ISP domain authorization methods
configuration,
42
AAA ISP domain creation,
40
AAA ISP domain methods configuration,
40
AAA ISP domain status configuration,
41
K
key modulus
creating local key pair,
116
key pair
security SSH DSA host key pair,
127
security SSH RSA host key pair,
127
security SSH RSA server key pair,
127
L
LAN
802.1X overview,
59