Creating Policies
64
ETEP CLI User Guide
Creating Local Site Policies
Local site policies allow you to create locally configured policies from the command line, without
requiring an EncrypTight ETKMS for key distribution. Using the local-site CLI commands you can create
manual key encryption policies, bypass policies, and discard policies at either Layer 2 or Layer 3. Mesh
policies can be created by defining policies that share the identical keys and SPIs on multiple ETEPs.
The primary use for local site policies is to facilitate in-line management in Layer 2 encrypted networks.
These policies supplement existing EncrypTight policies, adding the flexibility to encrypt or pass in the
clear specific Layer 3 routing protocols, or Layer 2 Ethertypes and VLAN IDs.
shows a network configuration that is managed in-line and protected using EncrypTight. The
local site ETEP (1) is on the same subnet as the EncrypTight management devices (2 and 3). The
management devices communicate with the remote site ETEPs (4) over the same link that is being
protected by the ETEPs.
Figure 10
In-line management of ETEPs
The local-site policy feature gives you the ability to define a set of policies for the in-line management
protocols that need to be passed through the ETEP, such as EIGRP, OSPF, RIPv2, or BGP. These policies
are high priority policies that are not affected when EncrypTight distributed key policies are deployed on
the ETEP.
This feature is similar to the ETEP configuration option that allows TLS traffic to pass through the
ETEPs in the clear, but it provides the additional flexibility of allowing you to specify several protocols
and ports, and to restrict the policy to specific IP addresses. The policy action can be defined as bypass,
protect, or discard. Protect policies allow the in-line management traffic to be encrypted with user-defined
manual keys.
Summary of Contents for ET0010A
Page 7: ...8 ETEP CLI User Guide Contents...
Page 15: ...Getting Started 16 ETEP CLI User Guide...
Page 33: ...User Administration 34 ETEP CLI User Guide...
Page 55: ...Configuring the ETEP 56 ETEP CLI User Guide...
Page 97: ...Creating Policies 98 ETEP CLI User Guide...
Page 101: ...Maintenance 102 ETEP CLI User Guide...
Page 119: ...Troubleshooting 120 ETEP CLI User Guide...
Page 123: ...FIPS 140 2 Level 2 Operation 124 ETEP CLI User Guide...
Page 205: ...Command Reference 206 ETEP CLI User Guide...
Page 211: ...Index 212 ETEP CLI User Guide...