Add_workflow_for_techpubs | ||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
Panel | ||||
---|---|---|---|---|
In this section:
|
This object is used to Use the SPD (Security Policy Database) window to configure IPsec SPD entries for the SBC. The SPD entries establishes the phase 2 criteria for negotiation between the SBC and the an IKE peer. The successful completion of this negotiation results in a Security Association (SA).
On the SBC main screen, navigate to All > Address Context >Ipsec IPsec > SPD.
The SPD can be checked for each Address Context or for all the Address Contexts created. Use the drop-down box to select the desired Address Context window opens.
Caption | ||||
---|---|---|---|---|
| ||||
The SPD window is displayed.
Caption | ||||
---|---|---|---|---|
| ||||
...
To edit any of the SPD in the list, click the radio button next to the specific SPD name.
Caption | ||||
---|---|---|---|---|
| ||||
The Edit Selected SPD window is displayed below.
Caption | ||||
---|---|---|---|---|
| ||||
Make the required changes and click Save at the right hand bottom of the panel to save the changes made.
To create a new SPD, click New SPD tab on the SPD List panel.
Caption | ||||
---|---|---|---|---|
| ||||
create a new SPD entry:
Use the drop-down box to select the desired Address Context for the SPD.
Click New SPD. The Create New SPD window opensThe Create New SPD window is displayed.
Caption | ||||
---|---|---|---|---|
| ||||
The following fields are displayed:
Caption | ||||
---|---|---|---|---|
| ||||
| ||||
Parameter | Length/Range | Description | ||||
---|---|---|---|---|---|---|
Name | 1-23 | Specifies the name of an IPsec Security Policy Database (SPD) entry. The IPsec SPD is an ordered list of entries ("rules") that specify sets of packets and determine whether or not to permit, deny, or protect packets between the You may create and configure up to 4,096 SPD entries. | ||||
State | NA | Administrative state to disable or enable a SPD entry. | ||||
Precedence | 0-65535 | A unique precedence (evaluation order) for this SPD. | ||||
Local |
IP Addr | N/A | Specifies the local IPv4 or IPv6 address of the SPD traffic selector. Zero indicates wildcard. |
Local |
IP Prefix Len | 0-128 | Specifies the local IP prefix length of the SPD traffic selector. Default value is 0. |
Local Port | 0-65535 | Specifies the local port of the SPD traffic selector. Zero indicates wildcard. Default value is 0. |
Remote |
IP Addr | NA | Specifies the remote IPv4 or IPv6 address of the SPD traffic selector. Zero indicates wildcard. |
Remote |
IP Prefix Len | 0-128 | Specifies the remote IP prefix length of the SPD traffic selector. Default value is 0. |
Remote Port | 0-65535 | Specifies the remote port of the SPD traffic selector. Zero indicates wildcard. Default value is 0. |
Protocol | 0-255 | Specifies the IP protocol number of the SPD traffic selector. This parameter uses IANA protocol number assignment, that is, protocol number 6 represents TCP, protocol number 17 represents UDP. Zero indicates wildcard. Default value is 0. |
Action | N/A | Action applied when packets processed by IPSEC found matching the selectors of this SPD rule.
|
| |
Mode | NA |
Note |
---|
This parameter is only applicable if the |
Use this parameter to set the IPsec mode for the SPD.
Notes:
|
...
|
To edit an SPD entry:
...
Caption | ||||
---|---|---|---|---|
| ||||
|
Click Copy SPD tab on the SPD List panel.
Caption | ||||
---|---|---|---|---|
| ||||
|
The Copy Selected SPD window is displayed along with the field details which can be edited.
Caption | ||||
---|---|---|---|---|
| ||||
...
To copy an SPD entry:
...
To delete any of the created SPD, click an SPD entry:
...
...
...
0 | Figure |
---|---|
1 | All - Address Context - Ipsec - Spd Highlighted |
...
...
...
Pagebreak |
---|
Caption | ||||
---|---|---|---|---|
| ||||
Click Yes to remove the specific SPD from the list.