Jump to content United States-English
HP.com Home Products and Services Support and Drivers Solutions How to Buy
» Contact HP
More options
HP.com home
HP-UX IPSec version A.01.06 Administrator's Guide: HP-UX 11i Version 2 > Chapter 3 Configuring HP-UX IPSec

Overview

» 

Technical documentation

Complete book in PDF
» Feedback
Content starts here

 » Table of Contents

 » Glossary

 » Index

There are five main configuration areas: IPSec policies, ISAKMP policies, preshared keys, security certificates (certificates and certificate IDs), and boot options.

Although you can configure these components in any order, HP recommends that you use the following procedure to configure IPSec:

  1. Start the ipsec_mgr configuration utility.

  2. Configure IPSec policies.

    An IPSec policy specifies the actions or transformations performed on IP packets traveling between IPSec systems. The main components of an IPSec policy are:

    1. IP packet filter (IP address, protocol, and port information)

    2. Transform (action) list

    3. ISAKMP policy name

    When an IP packet is initially sent or received, HP-UX IPSec uses the IP packet filters to select an IPSec policy. IPSec then takes an action according to the contents of the transform list. If the action is to authenticate or encrypt the packet, the ISAKMP policy is used to establish an ISAKMP Security Association (SA), so that IPSec SAs can be established for authentication or encryption.

  3. Configure ISAKMP policies.

    An ISAKMP policy defines the parameters used when negotiating an ISAKMP SA. These include the authentication and encryption algorithms, and the primary authentication method such as preshared keys or a certificate-based method, such as RSA signatures.

  4. Configure the IPSec tunnel, if you are using a tunnel.

  5. Configure preshared keys, if you are using preshared keys for IKE authentication.

  6. Configure security certificates and certificate IDs, if you are using RSA signatures for IKE authentication. This procedure is described in Chapter 4 “Using Certificates with HP-UX IPSec ”.

  7. Configure boot-up options. The boot-up options allow you to configure HP-UX IPSec to automatically start at system boot-up time and to specify general operating parameters.

  8. Verify the configuration.

  9. Print formatted IPSec and ISAKMP policies.

NOTE: HP-UX IPSec cannot be configured to selectively encrypt or authenticate services with dynamically assigned port numbers, such as the Network File Service (NFS) mountd, lockd, and statd services.

HP-UX IPSec also cannot be used to authenticate or encrypt IP packets with broadcast, subnet broadcast, multicast, or anycast IP addresses.

Printable version
Privacy statement Using this site means you accept its terms Feedback to webmaster
© 2003 Hewlett-Packard Development Company, L.P.