
Creating Local Site Policies
ETEP CLI User Guide
71
Related topics:
●
“Policy Deployment” on page 72
●
policy-selector
<remote-ip> <local-ip> <protocol> <remote-port> <local-port>
This command configures Layer 3 selectors.
The defaults are: 0.0.0.0/0 (remote ip), 0.0.0.0/0 (local ip), any (protocol), any
(remote port), any (local port).
remote-ip
IPv4 address and prefix or subnet mask of the endpoint on the far
side of the untrusted network. The ETEP accepts a CIDR prefix or dot-decimal
subnet mask. The default is set to 0.0.0.0/0, which means “process all packets”
coming from any address.
local-ip
IPv4 address and prefix or subnet mask of the local endpoint. The ETEP
accepts a CIDR prefix or dot-decimal subnet mask. The default is set to 0.0.0.0/
0, “process all packets.”
Protocol
A decimal value that identifies the IP layer protocol. “Any” accepts all
protocols. Range is 1-254.
Remote and local ports
A decimal value that identifies the transport layer protocol port number for the
remote or local endpoint. “Any” means “accept all.” Range is 1-65535
policy-manual-key
<direction>
<spi>
<encryptionAlgorithm>
<authenticationAlgorithm>
<encryptionKey>
<authenticationKey>
direction
{in | out | any}
Specifies the direction of the SA. The any attribute creates two bidirectional SAs
from a single command.
spi
-
Each SA must have a unique SPI. The SPI is a decimal value between
256 and 4096.
encryptionAlgorithm
{3des-cbc |aes256-cbc}
When the ETEP is configured for Layer 2 operation you must use aes256-cbc.
authenticationAlgorithm
{md5-96-hmac | sha1-96-hmac}
When the ETEP is configured for Layer 2 operation you must use sha1-96-hmac.
encryptionKey
Hexadecimal number with the appropriate length according to
the selected algorithm. Key lengths are listed in
. When in FIPS mode,
you have to enter the encryption and authentication keys twice.
authenticationKey
Hexadecimal number with the appropriate length according
to the selected algorithm. Key lengths are listed in
mode, you have to enter the encryption and authentication keys twice.
Table 38
Key lengths
Encryption algorithm
Encryption key length
(characters)
Authentication
algorithm
Authentication key
length (characters)
3des-cbc
48
md5-96-hmac
32
aes256-cbc
64
sha1-96-hmac
40
Table 37
Manual key policy commands
Command
Description
Содержание ET0010A
Страница 7: ...8 ETEP CLI User Guide Contents...
Страница 15: ...Getting Started 16 ETEP CLI User Guide...
Страница 33: ...User Administration 34 ETEP CLI User Guide...
Страница 55: ...Configuring the ETEP 56 ETEP CLI User Guide...
Страница 97: ...Creating Policies 98 ETEP CLI User Guide...
Страница 101: ...Maintenance 102 ETEP CLI User Guide...
Страница 119: ...Troubleshooting 120 ETEP CLI User Guide...
Страница 123: ...FIPS 140 2 Level 2 Operation 124 ETEP CLI User Guide...
Страница 205: ...Command Reference 206 ETEP CLI User Guide...
Страница 211: ...Index 212 ETEP CLI User Guide...