HP 635n HP Jetdirect Print Server Administrator's Guide - Page 108

IPsec Configuration, Table 5-1

Page 108 highlights

Table 5-1 IPsec Policy page Item Enable IPsec Allow all non-IPsec traffic Drop all non-IPsec traffic Description Enter a check mark in the checkbox to enable your IPsec policy. Clear this checkbox to disable IPsec operation. If IPsec is enabled, select a Default Policy for non-IPsec packets. The default setting is to discard (drop) non-IPsec packets for maximum security. Dropped packets will not be processed. You can choose to allow non-IPsec traffic to be processed as long as a configured IPsec rule is not violated. Example: IPsec is enabled on the print server with the following rule: ■ All IPv4 addresses ■ Printing services (Port 9100) ■ A simple IPsec template If Allow all non-IPsec traffic is enabled, then: ■ A non-IPsec packet with IPv4 address, directed to printing port 9100, would not be processed (dropped) because it violates the configured rule. ■ A non-IPsec packet with IPv4 address to the Telnet port would be allowed and processed. If Drop all non-IPsec traffic is enabled, then: ■ A non-IPsec packet with IPv4 address directed to printing port 9100 would not be processed (dropped) because it violates the configured rule. ■ An IPsec packet with IPv4 address directed to printing port 9100 would be allowed and processed because it matches the rule. ■ A non-IPsec packet with IPv4 address to the Telnet port would be dropped because of the Default Policy for non-IPsec packets. 98 Chapter 5 IPsec Configuration ENWW

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194

Table 5-1
IPsec Policy page
Item
Description
Enable IPsec
Enter a check mark in the checkbox to enable your IPsec policy. Clear this checkbox
to disable IPsec operation.
Allow all non-IPsec traffic
Drop all non-IPsec traffic
If IPsec is enabled, select a Default Policy for non-IPsec packets. The default setting
is to discard (drop) non-IPsec packets for maximum security. Dropped packets will
not be processed. You can choose to allow non-IPsec traffic to be processed as long
as a configured IPsec rule is not violated.
Example
: IPsec is enabled on the print server with the following rule:
All IPv4 addresses
Printing services (Port 9100)
A simple IPsec template
If
Allow all non-IPsec traffic
is enabled, then:
A non-IPsec packet with IPv4 address, directed to printing port 9100, would
not
be processed (dropped) because it violates the configured rule.
A non-IPsec packet with IPv4 address to the Telnet port would be allowed and
processed.
If
Drop all non-IPsec traffic
is enabled, then:
A non-IPsec packet with IPv4 address directed to printing port 9100 would
not
be
processed (dropped) because it violates the configured rule.
An IPsec packet with IPv4 address directed to printing port 9100 would be
allowed and processed because it matches the rule.
A non-IPsec packet with IPv4 address to the Telnet port would be dropped
because of the Default Policy for non-IPsec packets.
98
Chapter 5
IPsec Configuration
ENWW