HP StorageWorks 8/20q HP StorageWorks 8/20q Fibre Channel Switch command line - Page 175

Direction, Priority, Action, ProtectionDesired, ahRuleLevel, ipsec save

Page 175 highlights

Table 15 Policy configuration parameters (continued) Parameter Direction Priority Action ProtectionDesired ahRuleLevel espRuleLevel Description Direction of the data traffic to which the policy is to be applied: • In-Data entering the source • Out-Data leaving the source A number from -2147483647 to +214783647 that determines priority for this policy in the security policy database. The higher the number, the higher the priority. Processing to apply to data traffic: • Discard-Unconditionally disallow all inbound or outbound data traffic. • None-Allow all inbound or outbound data traffic without encryption or decryption. • Ipsec-Apply IP security to inbound and outbound data traffic. Type of IP security protection to apply: • AH-Authentication Header • ESP-Encapsulating Security Payload • Both-Apply both AH and ESP protection Rule level to apply for AH protection: • Default-Use the system wide default for the protocol • Use-Use a security association if one is available • Require-A security association is required whenever a packet is sent that is matched with the policy Rule level to apply for ESP protection: • Default-Use the system wide default for the protocol • Use-Use a security association if one is available • Require-A security association is required whenever a packet is sent that is matched with the policy Operands delete [policy] Deletes the policy given by [policy] from the Security Policy database. You must enter the ipsec save command afterwards to save your changes. edit [policy] Opens an edit session in which to change the configuration of an existing policy given by [policy]. list [option] Displays the configuration for the policies given by [option]. If you omit [option], the command displays the configuration of all active policies. [option] can be one of the following: [policy] Displays the configuration for the policy given by [policy]. active Displays the configuration for all active policies. configured Displays the configuration for all user-defined policies. edited Displays the configuration for all policies that have been modified, but not saved. 8/20q Fibre Channel Switch command line interface guide 175

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332

8/20q Fibre Channel Switch command line interface guide
175
Direction
Direction of the data traffic to which the policy is to be applied:
In—Data entering the source
Out—Data leaving the source
Priority
A number from –2147483647 to +214783647 that determines
priority for this policy in the security policy database. The higher the
number, the higher the priority.
Action
Processing to apply to data traffic:
Discard—Unconditionally disallow all inbound or outbound
data traffic.
None—Allow all inbound or outbound data traffic without
encryption or decryption.
Ipsec—Apply IP security to inbound and outbound data traffic.
ProtectionDesired
Type of IP security protection to apply:
AH—Authentication Header
ESP—Encapsulating Security Payload
Both—Apply both AH and ESP protection
ahRuleLevel
Rule level to apply for AH protection:
Default—Use the system wide default for the protocol
Use—Use a security association if one is available
Require—A security association is required whenever a packet is
sent that is matched with the policy
espRuleLevel
Rule level to apply for ESP protection:
Default—Use the system wide default for the protocol
Use—Use a security association if one is available
Require—A security association is required whenever a packet is
sent that is matched with the policy
Table 15
Policy configuration parameters
(continued)
Parameter
Description
Operands
del
ete [policy]
Deletes the policy given by [policy] from the Security Policy database. You must enter the
ipsec save
command afterwards to save your changes.
edit [policy]
Opens an edit session in which to change the configuration of an existing policy given by
[policy].
list
[option]
Displays the configuration for the policies given by [option]. If you omit [option], the command
displays the configuration of all active policies. [option] can be one of the following:
[policy]
Displays the configuration for the policy given by [policy].
active
Displays the configuration for all active policies.
configured
Displays the configuration for all user-defined policies.
edited
Displays the configuration for all policies that have been modified, but not saved.