![STRIDE SE-MC2U-SC Скачать руководство пользователя страница 139](http://html1.mh-extra.com/html/stride/se-mc2u-sc/se-mc2u-sc_user-manual_1384646139.webp)
The AH IPsec protocol is used for authentication. It uses cryptography to detect that the
sender has the same hash key the receiver does. It does not provide any secrecy in transit.
The ESP protocol is used for encryption. It uses cryptography to hide the contents of traffic
in transit from anyone who does not have the secret key it was encrypted with.
IPComp is used to compress traffic. It does not provide any secrecy or authenticity
guarantees.
Security Policy Database:
This section is used to create, delete, and modify SPD entries.
To create an SPD entry, click “Add SPD Rule” and set the source, destination, direction, and
protocol requirements as appropriate. To save your changes, click Commit Changes.
To delete an SPD entry, click the ‘X’ button at the end of the row and click Commit
Changes.
To modify an SPD entry, change parameters as desired and click Commit Changes.
• Source:
An address of the form address, address/prefixlen, address/prefixlen[port], or address[port].
This specifies the source host or hosts that this policy will affect.
• Destination:
An address in one of the same forms accepted by the Source field. This specifies the
destination host or hosts that this policy will affect.
• Direction:
The direction traffic is traveling through the switch. If the switch’s address is specified
in the source field, the direction should be Out. If the switch’s address is in the destination field,
the direction should be In.
• ESP:
Whether to require encryption for communication between the specified hosts.
• Authentication (AH):
Whether to require authentication for communication between the specified
hosts.
• IPComp:
Whether to require compression for communication between the specified hosts.
• Delete:
When the button is clicked, this SPD entry will be deleted when changes are committed.
Security Association Database:
To create an SAD entry, click “Add Security Association” and set the source, destination, SPI,
mode, cipher, hash algorithm, and keys as appropriate. To save your changes, click Commit
Changes.
CAUTION: Take care when configuring SAD entries. If the keys and SPI values are not the same on
two communicating hosts and their security policies require encryption or authentication they will be
unable to successfully communicate. You may find yourself unable to communicate with the Switch.
NOTE:
SPD entries will not apply to ICMPv6 Neighbor Discovery traffic. This allows Neighbor Discovery to function
together with IKE. (Internally, the system adds high-priority rules bypassing IPsec for Neighbor Advertisement and
Neighbor Solicitation packets.)
CAUTION: Take care when configuring SPD entries. If you do not configure appropriate SAD entries to
go along with them and an SPD entry affects the host you are using to configure the Switch, you may
find yourself unable to communicate with the Switch
4-55
Chapter 4 - Managed Switch Software Setup
Stride Industrial Ethernet Switches User Manual 2nd Ed. Rev. A
Содержание SE-MC2U-SC
Страница 1: ...Manual Number SE USER M Industrial Ethernet Switches and Media Converters USER MANUAL...
Страница 2: ......
Страница 6: ......
Страница 8: ......
Страница 14: ......
Страница 50: ......
Страница 85: ...This page intentionally left blank...
Страница 132: ...Switch 2 4 48 Chapter 4 Managed Switch Software Setup Stride Industrial Ethernet Switches User Manual 2nd Ed Rev A...
Страница 133: ...Switch 3 4 49 Chapter 4 Managed Switch Software Setup Stride Industrial Ethernet Switches User Manual 2nd Ed Rev A...
Страница 168: ......
Страница 169: ...Glossary UL C US R In This Appendix Glossary of Terms B 2 B B B Appendix Appendix Appendix...
Страница 229: ......
Страница 230: ......