![Brocade Communications Systems ICX 7250 series Скачать руководство пользователя страница 252](http://html1.mh-extra.com/html/brocade-communications-systems/icx-7250-series/icx-7250-series_configuration-manual_2817203252.webp)
OSPFv3 non-stop routing
OSPFv3 can continue operation without interruption during hitless failover when the NSR feature is enabled.
During graceful restart (GR), the restarting neighbors must help build routing information during a failover. However, the GR helper may
not be supported by all devices in a network. Non-stop routing (NSR) eliminates this dependency.
NSR does not require support from neighboring devices to perform hitless failover, and OSPF can continue operation without
interruption.
NOTE
NSR does not support IPv6-over-IPv4 tunnels and virtual links, so traffic loss is expected while performing hitless
failover.
IPsec for OSPFv3
IP Security (IPsec) secures OSPFv3 communications by authenticating and encrypting each IP packet of a communication session.
IPsec provides security features such as data integrity, replay protection, and message confidentiality. You can use IPsec to secure
specific OSPFv3 areas and interfaces and protect OSPFv3 virtual links.
The Encapsulating Security Payload (ESP) protocol authenticates routing information between peers. ESP can provide message
confidentiality, connectionless data integrity, and optional replay protection. ESP has both a header and a trailer. The authentication data
of ESP cannot protect the outer IP header, only the payload that is being encrypted.
IPsec is available for OSPFv3 traffic only and only for packets that are “for-us”. A for-us packet is addressed to one of the IPv6
addresses on the device or to an IPv6 multicast address. Packets that are only forwarded by the line card do not receive IPsec scrutiny.
Brocade devices support the following components of IPsec for IPv6-addressed packets:
•
Authentication through ESP in transport mode
•
Hashed Message Authentication Code-Secure Hash Algorithm 1 (HMAC-SHA-1) as the authentication algorithm
•
Security parameter index (SPI)
•
Manual configuration of keys
•
Configurable rollover timer
IPsec can be enabled on the following logical entities:
•
Interface
•
Area
•
Virtual link
IPsec is based on security associations (SAs). With respect to traffic classes, this implementation of IPsec uses a single security
association between the source and destination to support all traffic classes and does not differentiate between the different classes of
traffic that the DSCP bits define.
IPsec on a virtual link is a global configuration. Interface and area IPsec configurations are more granular.
Among the entities that can have IPsec protection, the interfaces and areas can overlap. The interface IPsec configuration takes
precedence over the area IPsec configuration when an area and an interface within that area use IPsec. Therefore, if you configure IPsec
for an interface and an area configuration also exists that includes this interface, the interface's IPsec configuration is used by that
interface. However, if you disable IPsec on an interface, IPsec is disabled on the interface even if the interface has its own specific
authentication.
OSPFv3 non-stop routing
Brocade FastIron Layer 3 Routing Configuration Guide
252
53-1003903-04
Содержание ICX 7250 series
Страница 2: ...Brocade FastIron Layer 3 Routing Configuration Guide 2 53 1003903 04...
Страница 16: ...Brocade FastIron Layer 3 Routing Configuration Guide 16 53 1003903 04...
Страница 20: ...Brocade FastIron Layer 3 Routing Configuration Guide 20 53 1003903 04...
Страница 36: ...Brocade FastIron Layer 3 Routing Configuration Guide 36 53 1003903 04...
Страница 124: ...Brocade FastIron Layer 3 Routing Configuration Guide 124 53 1003903 04...
Страница 174: ...Brocade FastIron Layer 3 Routing Configuration Guide 174 53 1003903 04...
Страница 188: ...Brocade FastIron Layer 3 Routing Configuration Guide 188 53 1003903 04...
Страница 202: ...Brocade FastIron Layer 3 Routing Configuration Guide 202 53 1003903 04...
Страница 470: ...Brocade FastIron Layer 3 Routing Configuration Guide 470 53 1003903 04...