
Configuring IPsec Services
D-2
308630-15.1 Rev 00
Web Browser Configuration of the Contivity VPN Switch
Unlike products that use BayRS software, you configure Contivity products
through a Web browser. If you are new to Contivity configuration, note the
following general guidelines when you configure Contivity software using the
browser:
• You must click on OK at the bottom of Contivity configuration screens to
continue as you configure the Contivity software. If you use your browser
navigation buttons, your configuration choices will be lost.
• All configuration changes are dynamic, either taking place immediately or
taking effect for subsequent IKE/IPsec connections made to the peer.
IPsec Terminology
Contivity software uses different terminology than BayRS for some IPsec
features. Table D-1
lists some of these terms.
In general, when you refer to security associations (SAs), especially if you are
troubleshooting a new configuration, it is helpful to specify the type of SA that
you are referring to: an IKE SA or an IPsec SA.
In addition, the BayRS implementation of IPsec uses the term protocol in protocol
filtering criteria for an IPsec policy template or policy. This term is not
comparable to the Contivity filters’ protocol options. BayRS IPsec uses protocol
as the value for protocol selector as defined in IETF RFCs for IPsec. The
Contivity VPN Switch does not support the protocol selector defined in the RFCs.
Table D-1. Comparison of BayRS and Contivity IPsec Terminology
BayRS Term Contivity Equivalent
Security association (SA) formed by
two IKE security gateways or peers
IPsec branch office connection
IPsec SAs IPsec branch office sessions
Policy Branch office connection’s remote and local
accessible networks
Policy proposal Branch office connection’s group IPsec
encryption and rekey information
Komentarze do niniejszej Instrukcji