
Configuring IP Security Services
C-2
304111-A Rev 00
Figure C-1. IPsec Outbound Policies for Routers 1, 2, and 3
Example 1: Required Policies on RTR 1 to Protect Data Between
RTR 1 Subnet 192.32.5.0 and RTR 2 Subnet 192.28.41.0
Router RTR 1 Interface S21
Policy
Outbound
Action
Protect
Criteria
IP source address range: 192.32.5.0 - 192.32.5.255
IP destination address range: 192.28.41.0 - 192.28.41.255
SA
SRC: 1.1.1.1 DST: 1.1.1.2 SPI 256
RTR1 Interface S21
Security Policy
Outbound Inbound
Action
Bypass Bypass
Criteria
Protocol 89 (OSPFIGP) Protocol 89 (OSPFIGP)
12
12
12
RTR1
RTR2
RTR3
Protect / Unprotect SA
RTR1 to RTR2
SPI 256
Protect / Unprotect SA
RTR2 to RTR3
SPI 256
Protect / Unprotect SA
RTR1 to RTR3
SPI 257
IP / IPsec / OSPF(Type: NBMA)
IP / IPsec / RIP
S21
1.1.1.1
S31
2.2.2.1
S11
2.2.2.2
192.32.5.0
192.28.41.0
192.131.141.0
S21
1.1.1.2
Komentarze do niniejszej Instrukcji