
Creating Policies
58
ETEP CLI User Guide
Defining a Layer 2 Point-to-Point Policy
The
layer2-p2p
command allows an Administrator user to define a Layer 2 point-to-point policy on the
ETEP. This command is available from policies mode.
To configure a Layer 2 point-to-point policy on the ETEP
:
1 Log in to the CLI as the Administrator user.
2 At the
admin
> prompt, type
configure
and press ENTER.
3 At the
config
> prompt, type
policies
and press ENTER.
4 At the
policies>
prompt, enter the
layer2-p2p
command. See
for a description of the
attributes.
layer2-p2p {<traffic-handling>} [<role>] [<auth-method>] [<preshared-key>]
[<group-id>]
The policy does not take effect until the ETEP has been configured to operate in Layer 2 point-to-
point mode using the
policy-mode
CLI command (see
“Configuring the Policy Mode” on page 59
).
5 Configure a policy on the companion ETEP to use the identical preshared key and group ID. The
companion ETEP must be assigned the
opposite
role of its peer (primary or secondary).
Table 28
layer2-p2p command description
Attribute
Description
Traffic-handling
{encrypt | clear | discard}
The ETEP has three options for processing packets:
•
Encrypt all packets
•
Discard all packets
•
Pass all packets in the clear
Under normal operation, the ETEP is configured to encrypt all traffic that is
exchanged between two peer appliances. This is the ETEP’s default mode. Other
methods of traffic handling are used for debugging and troubleshooting.
Role
[primary | secondary]
When the traffic-handling attribute is set to encrypt, one of the ETEPs must be
assigned the primary role and the other the secondary role. The appliance role is
used in the process of establishing a security association (SA) between ETEP
peers. The ETEPs will not function properly if both appliances are configured with
the same role.
The role is not used when the traffic-handling attribute is set to discard or clear.
Auth-method
preshared-key
The ETEP uses the preshared key string to authenticate its peer’s identity before
beginning to negotiate the SAs.
Содержание ET0010A
Страница 7: ...8 ETEP CLI User Guide Contents...
Страница 15: ...Getting Started 16 ETEP CLI User Guide...
Страница 33: ...User Administration 34 ETEP CLI User Guide...
Страница 55: ...Configuring the ETEP 56 ETEP CLI User Guide...
Страница 97: ...Creating Policies 98 ETEP CLI User Guide...
Страница 101: ...Maintenance 102 ETEP CLI User Guide...
Страница 119: ...Troubleshooting 120 ETEP CLI User Guide...
Страница 123: ...FIPS 140 2 Level 2 Operation 124 ETEP CLI User Guide...
Страница 205: ...Command Reference 206 ETEP CLI User Guide...
Страница 211: ...Index 212 ETEP CLI User Guide...