Jump to content United States-English
HP.com Home Products and Services Support and Drivers Solutions How to Buy
» Contact HP
More options
HP.com home
HP-UX IPSec version A.02.00 Administrator's Guide: HP-UX 11i version 1 and HP-UX 11i version 2 > Chapter 1 HP-UX IPSec Overview

HP-UX IPSec Topologies

» 

Technical documentation

Complete book in PDF
» Feedback
Content starts here

 » Table of Contents

 » Glossary

 » Index

IPSec can be employed between hosts (that is, end nodes), between gateways, or between a host and a gateway in an IP network. HP-UX IPSec can only be installed on end nodes.

Installing HP-UX IPSec on an HP-UX system that is a router or gateway is not supported, except when the system is used as an HP-UX Mobile IPv6 Home Agent. See Chapter 7 “HP-UX IPSec and HP-UX Mobile IPv6” for more information.

Host-to-Host Topology

Two end hosts can run HP-UX IPSec locally to protect communication between them, with or without intermediate gateways.

Figure 1-11 IPSec Host-to-Host Topology

IPSec Host-to-Host Topology

Host-to-Gateway Topology

In situations where the local subnet is a trusted network, you can use HP-UX IPSec between an end host and a gateway and create a secure Virtual Private Network (VPN).

Figure 1-12 Host-to-Gateway (VPN) Topology

Host-to-Gateway (VPN) Topology
NOTE: In an Host-to-Gateway topology, the gateway cannot be an HP-UX system unless the gateway is an HP-UX Mobile IPv6 Home Agent, and the gateway functionality is used only to forward packets for Mobile IPv6.

Host-to-Host Tunnel Topology

Two end hosts with HP-UX IPSec protection can configure a tunnel policy that securely protects traffic between them. The tunnel adds extra protection; an intruder cannot see the real IP headers of packets traveling between the hosts.

The host-to-host tunnel topology is commonly used in an iSCSI environment.

Figure 1-13 Host-to-Host Tunnel Topology

Host-to-Host Tunnel Topology

Gateway-to-Gateway Topology

Two hosts each reside upon insecure networks (such as insecure intranets). These hosts need to communicate securely over an insecure public network (such as the Internet). HP-UX IPSec can be used over a tunnel between two (non-HP) IPSec gateways to provide additional end-to-end security.

Figure 1-14 IPSec Gateway-to-Gateway Topology

IPSec Gateway-to-Gateway Topology
Printable version
Privacy statement Using this site means you accept its terms Feedback to webmaster
© 2004 Hewlett-Packard Development Company, L.P.