Commands
ETEP CLI User Guide
155
peer. One of the ETEPs must be assigned the primary role and the other the secondary role. The role is
not used when traffic-handling is set to clear or discard.
auth-method - preshared-key
The authentication method used in Layer 2 point-to-point policies is preshared keys.
preshared-key -
The preshared key is a case-sensitive alphanumeric string from 8-255 characters in
length. Valid characters are upper and lower alpha characters, and numbers 0-9. All special characters are
allowed
except
the following: ? “ { } [ ] ( ) = \ < > & and #. To include a space, enclose it in double
quotes.The default key value is 01234567.
group-id
-
Valid group ID values range from 0-9. The default value is 0.
Usage Guidelines
Consider the following when configuring a Layer 2 point-to-point policy:
●
When traffic-handling is set to clear or discard, no other parameters are required. Role, auth-method,
preshared-key, and group-id apply only to encrypted traffic.
●
When the traffic-handling attribute is set to encrypt, one of the ETEPs must be assigned the primary
role and the other the secondary role. The appliance role is used in the process of establishing security
associations (SAs) between a pair of ETEPs.
●
Both ETEPs must use the same preshared key and group ID.
●
The policy does not take effect until the
policy-mode
command has been configured for Layer 2
point-to-point operation.
The ETEP uses preshared keys to authenticate the identities of the communicating parties during IKE
Phase 1 negotiation. The ETEPs use IKE negotiations to establish security associations (SAs) between
peer appliances.
In a point-to-point network, the two ETEPs must be configured with the same group ID in order to
communicate properly with each other. If you are using only one pair of ETEPs in the same subnet you
can use the default group ID.
If more than one pair of ETEPs is used within the same Layer 2 network, the group ID isolates the traffic
from one pair of ETEPs from any other pair. Each appliance can belong to only one group.
Example
The first example configures the ETEP to encrypt all traffic, assigns the secondary role to the ETEP,
defines a preshared key, and sets the group ID to 0.
layer2-p2p encrypt secondary preshared-key myPr3Shar3dK3y 0
The next example configures the ETEP to pass all traffic in the clear.
layer2-p2p clear
license
Description
The
license
command enables the appropriate throughput speed on the ETEP.
Содержание ET0010A
Страница 7: ...8 ETEP CLI User Guide Contents...
Страница 15: ...Getting Started 16 ETEP CLI User Guide...
Страница 33: ...User Administration 34 ETEP CLI User Guide...
Страница 55: ...Configuring the ETEP 56 ETEP CLI User Guide...
Страница 97: ...Creating Policies 98 ETEP CLI User Guide...
Страница 101: ...Maintenance 102 ETEP CLI User Guide...
Страница 119: ...Troubleshooting 120 ETEP CLI User Guide...
Страница 123: ...FIPS 140 2 Level 2 Operation 124 ETEP CLI User Guide...
Страница 205: ...Command Reference 206 ETEP CLI User Guide...
Страница 211: ...Index 212 ETEP CLI User Guide...