© Copyright Lenovo 2017
Chapter 25: Using IPsec with IPv6
425
2.
Decide
whether
to
use
tunnel
or
transport
mode.
The
default
mode
is
transport.
3.
To
describe
the
packets
to
which
this
policy
applies,
create
a
traffic
selector
using
the
following
commands:
where
the
following
parameters
are
used:
traffic
selector
number
an
integer
from
1
‐
10
permit|deny
whether
or
not
to
permit
IPsec
encryption
of
traffic
that
meets
the
criteria
specified
in
this
command
proto/any
apply
the
selector
to
any
type
of
traffic
proto/icmp
type
|any
only
apply
the
selector
only
to
ICMP
traffic
of
the
specified
type
(an
integer
from
1
‐
255)
or
to
any
ICMP
traffic
proto/tcp
only
apply
the
selector
to
TCP
traffic
source
IP
address
|any
the
source
IP
address
in
IPv6
format
or
“any”
source
destination
IP
address
|any
the
destination
IP
address
in
IPv6
format
or
“any”
destination
prefix
length
(Optional)
the
length
of
the
destination
IPv6
prefix;
an
integer
from
1
‐
128
Permitted
traffic
that
matches
the
policy
in
force
is
encrypted,
while
denied
traffic
that
matches
the
policy
in
force
is
dropped.
Traffic
that
does
not
match
the
policy
bypasses
IPsec
and
passes
through
clear
(unencrypted).
4.
Choose
whether
to
use
a
manual
or
a
dynamic
policy.
CN 4093(config)#
ipsec transform-set tunnel
|
transport
CN 4093(config)#
ipsec traffic-selector
<traffic
selector
number>
{permit|deny}
{any|icmp {
<ICMPv6
type>
|any}|tcp}
{
<source
IP
address>
|
any}
{
<destination
IP
address>
|
|any}
[
<prefix
length>
]
Содержание Flex System Fabric CN4093
Страница 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Страница 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Страница 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Страница 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Страница 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Страница 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Страница 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Страница 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Страница 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Страница 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Страница 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Страница 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Страница 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Страница 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Страница 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Страница 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Страница 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Страница 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Страница 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Страница 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Страница 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Страница 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Страница 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Страница 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Страница 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Страница 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Страница 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Страница 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Страница 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Страница 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Страница 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Страница 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Страница 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Страница 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Страница 633: ......
Страница 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...