Command Reference
196
ETEP CLI User Guide
transparent-mode-enable
Description
The
transparent-mode-enable
command configures whether the ETEP is viewable from a network
standpoint. When operating in transparent mode, the local and remote ports do not utilize user-assigned
IP addresses.
User Type
Administrator
Hierarchy Level
Configuration mode
Syntax
transparent-mode-enable {true | false}
Usage Guidelines
Transparent mode
is the ETEP’s default mode of operation on the local and remote ports. It is required
for Layer 2 policies and is appropriate for most distributed key policies. When operating in transparent
mode the ETEP preserves the network addressing of the protected networks by copying the original
source IP and MAC addresses from the incoming packet to the outbound packet header.
In transparent mode, the ETEP is not viewable from a network standpoint. The local and remote ports do
not utilize user-assigned IP addresses. In Layer 3 IP networks the local and remote ports cannot be
contacted through an IP address, and they do not respond to ARPs. The ETEP is also transparent in
Ethernet networks when configured as a Layer 2 encryptor.
If you want to conceal the original source IP address when sending encrypted traffic, configure the ETEP
to operate in
non-transparent mode
. Non-transparent mode is also used when sending traffic over the
internet. Since private IP addresses cannot be routed over the internet, any traffic between private
networks transmitted over the internet must use public IP addresses.
In non-transparent mode, the original source IP address in the outbound packet header is replaced with
either an IP address for the remote port or a virtual IP address. The ETEP port MAC address is used as
the packet’s source MAC address. You must assign IP addresses to the local and remote ports when
configuring the ETEP for this mode of operation.
Non-transparent mode applies only when the ETEP’s policy mode is set to Layer 3. To place the ETEP in
a non-transparent mode of operation, first configure the local and remote IP addresses, and then set the
transparent-mode-enable command to false. See the
EncrypTight User Guide
for more information about
addressing options and creating policies using virtual IP addresses.
Example
The following example disables transparent mode on the ETEP.
admin>
configure
config>
transparent-mode-enable false
Содержание ET0010A
Страница 7: ...8 ETEP CLI User Guide Contents...
Страница 15: ...Getting Started 16 ETEP CLI User Guide...
Страница 33: ...User Administration 34 ETEP CLI User Guide...
Страница 55: ...Configuring the ETEP 56 ETEP CLI User Guide...
Страница 97: ...Creating Policies 98 ETEP CLI User Guide...
Страница 101: ...Maintenance 102 ETEP CLI User Guide...
Страница 119: ...Troubleshooting 120 ETEP CLI User Guide...
Страница 123: ...FIPS 140 2 Level 2 Operation 124 ETEP CLI User Guide...
Страница 205: ...Command Reference 206 ETEP CLI User Guide...
Страница 211: ...Index 212 ETEP CLI User Guide...