HP 635n Practical IPsec Deployment for Printing and Imaging Devices - Page 99

ICMPv6 Neighbor

Page 99 highlights

Select the tab "IPsec Settings". If you ever use IPv6 addresses in this wizard, you MUST perform this step. ICMPv6 Neighbor Solicitations/Advertisements are used to provide basic communication via IPv6. If this is not selected, IPv6 communication will not even happen. NOTE: It appears that Vista with Service Pack 1 will allow ICMPv6 Neighbor Discovery packets to be sent/received without IPsec protection even when "NO (default)" is selected. Windows Server 2008 also allows ICMPv6 Neighbor Discovery packets at the default setting. Done! We have covered some basic IPsec policy deployments and actually stepped through the configuration process for both Jetdirect and Microsoft Windows. The only problem that we have is that we have been using Preshared Key authentication - which isn't recommended by Microsoft or HP for production deployments. We need to cover IPsec authentication for Certificates and Kerberos as we come closer and closer to being able to deploy IPsec in a production environment for printing and imaging devices. 99

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193

99
Done!
We have covered some basic IPsec policy deployments and actually stepped through the
configuration process for both Jetdirect and Microsoft Windows.
The only problem that we have is
that we have been using Preshared Key authentication – which isn’t recommended by Microsoft or HP
for production deployments.
We need to cover IPsec authentication for Certificates and Kerberos as
we come closer and closer to being able to deploy IPsec in a production environment for printing and
imaging devices.
Select the tab
“IPsec Settings”.
If you ever use IPv6
addresses in this wizard,
you MUST perform this
step.
ICMPv6 Neighbor
Solicitations/Advertisements
are used to provide basic
communication via IPv6.
If
this is not selected, IPv6
communication will not
even happen.
NOTE: It appears that Vista
with Service Pack 1 will
allow ICMPv6 Neighbor
Discovery packets to be
sent/received without IPsec
protection even when “NO
(default)” is selected.
Windows Server 2008 also
allows ICMPv6 Neighbor
Discovery packets at the
default setting.