
Security Policy and Security Association Examples
304111-A Rev 00
C-5
Example 6: Required Policies on RTR 2 to Allow ESP Traffic to Pass
Through and OSPF to Exchange Routing Updates Between
RTR 1 and RTR 2
Example 7: Required Policies on RTR 3 to Protect Data Between
RTR 3 Subnet 192.131.141.0 and RTR 1 192.32.5.0
RTR2 Interface S21
Security Policy
Outbound Inbound
Action
Bypass Bypass
Criteria
Protocol 89 (OSPFIGP) Protocol 89 (OSPFIGP)
Security Policy
Outbound Inbound
Action
Bypass Bypass
Criteria
Protocol 50 (ESP) Protocol 50 (ESP)
RTR2 Interface S31
Security Policy
Outbound Inbound
Action
Bypass Bypass
Criteria
Protocol 50 (ESP) Protocol 50 (ESP)
Router RTR 3 Interface S11
Policy
Outbound
Action
Protect
Criteria
IP source address range: 192.131.141.0 - 192.131.141.255
IP destination address range: 192.32.5.0 - 192.32.5.255
SA
SRC: 2.2.2.2 DST:1.1.1.1 SPI 257
Komentarze do niniejszej Instrukcji