Creating Layer 2 Point-to-Point Policies
ETEP CLI User Guide
59
Example
The following example configures the ETEP to encrypt all traffic, assigns the secondary role to the
ETEP, defines a preshared key, and sets the group ID to 0.
admin>
configure
config>
policies
policies>
layer2-p2p encrypt secondary preshared-key MyS3cr31tK3y 0
The next example configures the ETEP to pass all traffic in the clear.
admin>
configure
config>
policies
policies>
layer2-p2p clear
Configuring the Policy Mode
The
policy-mode
command allows an Administrator user to configure the encryption policy settings for
the ETEP. This includes the following:
●
Configure the ETEP for use in Layer 2 or Layer 3 policies
●
Enable or disable EncrypTight policy management
●
Enable or disable passing TLS traffic in the clear, which allows TLS-based management traffic to pass
unencrypted.
When ETEPs are shipped from the factory, their default policy mode is Layer 3, EncrypTight policy
management is enabled, and TLS traffic passes in the clear. Several of these settings need to be modified
for Layer 2 point-to-point operation.
Preshared-key
We recommend that you change the key from its default value of 01234567 prior
to deploying the ETEP.
The identical key value must be entered in both
appliances.
Note the following conventions when creating a preshared key:
•
The key is a case-sensitive alphanumeric string from 8-255 characters in
length.
•
Valid characters are upper and lower alpha characters, numbers 0-9
•
All special characters are allowed except the following: ? “ { } [ ] ( ) = \ < > &
and #
•
To include a space, enclose it in double quotes.
Group-id
Valid group ID values range from 0-9. The default value is 0.
A pair of ETEPs must be configured with the same group ID in order to
communicate properly with each other. If you are using only one pair of ETEPs in
the same subnet you can use the default group ID.
If more than one pair of ETEPs is used within the same Layer 2 network, the
group ID isolates the traffic from one pair of ETEPs from any other pair. Each
appliance can belong to only one group.
Table 28
layer2-p2p command description
Attribute
Description
Содержание ET0010A
Страница 7: ...8 ETEP CLI User Guide Contents...
Страница 15: ...Getting Started 16 ETEP CLI User Guide...
Страница 33: ...User Administration 34 ETEP CLI User Guide...
Страница 55: ...Configuring the ETEP 56 ETEP CLI User Guide...
Страница 97: ...Creating Policies 98 ETEP CLI User Guide...
Страница 101: ...Maintenance 102 ETEP CLI User Guide...
Страница 119: ...Troubleshooting 120 ETEP CLI User Guide...
Страница 123: ...FIPS 140 2 Level 2 Operation 124 ETEP CLI User Guide...
Страница 205: ...Command Reference 206 ETEP CLI User Guide...
Страница 211: ...Index 212 ETEP CLI User Guide...