You can create multiple IPsec links on the Bandura Cyber TIG. Once you establish a link, IPsec
will automatically and transparently encrypt all communications, protocols, and services along
that link.
Here are the available actions for IPsec Settings:
Enable Connection
Turn on the IPsec channel; peer node must be online
Edit Connection
Edit settings for the IPsec communications channel
Delete Connection
IPsec connection cannot be deleted until it is disabled first
You must have the
Crypto Admin
role to create an IPsec connection.
Once you have added your IPsec connection, the Bandura Cyber TIG will take you back to the
IPsec settings screen. Click the
Enable Connections
icon to turn on the secure
communications channel.
Things to consider before creating an IPsec connection:
● Do not use Tunnel mode when your Bandura Cyber TIG is on the same network as your
destination, since your data will travel twice on the same network: once encrypted and
once decrypted, and so may defeat the purpose of IPsec. This also degrades network
performance.
● In Tunnel mode, your data travels unencrypted
between your peer and destination. Your
peer should be directly connected to your destination network, otherwise you must trust
all other intervening networks and routes.
● Do not use Authentication
Headers
(AH
) in Transport mode if your communication goes
through a Network
Address
Translation
(NAT
) device. NAT is a technology that allows
multiple devices to share a single Internet address. Since AH ensures that the source
and destination Internet Addresses are valid and unchanged, this translation will cause
invalidation of the AH, and the communications will be rejected by the destination.
53