SROS Command Line Interface Reference Guide
Demand Interface Configuration Command Set
5991-2114
© Copyright 2007 Hewlett-Packard Development Company, L.P.
828
crypto map
<mapname>
Use the
crypto map
command to associate crypto maps with the interface.
Syntax Description
<mapname>
Assigns a crypto map name to the interface.
Default Values
By default, no crypto maps are assigned to an interface.
Functional Notes
When configuring a system to use both the stateful inspection firewall and IKE negotiation for VPN, keep
the following notes in mind.
When defining the policy class and associated access-control lists (ACLs) that describe the behavior of the
firewall, do not forget to include the traffic coming into the system over a VPN tunnel terminated by the
system. The firewall should be set up with respect to the unencrypted traffic that is destined to be sent or
received over the VPN tunnel. The following diagram represents typical SROS data-flow logic.
Note
When you apply a map to an interface, you are applying all crypto maps with the given
map name. This allows you to apply multiple crypto maps if you have created maps which
share the same name but have different map index numbers.
For VPN configuration example scripts, refer to the
VPN Configuration Guide
located on
the
ProCurve SROS Documentation
CD provided with your unit.
Содержание ProCurve Secure 7102dl
Страница 2: ......
Страница 3: ...SROS Command Line Interface Reference Guide Software Version J 08 03 September 2007 61195880L1 35H ...
Страница 1454: ......