Black Box ET0010A, ET1000A, EncrypTight, ET0100A Remote and Local Port Settings, Transparent Mode

Page 305

ETEP Configuration

Table 85

Link speeds on the management port

 

 

 

 

 

Link speed

Auto-negotiate

Auto-negotiate

Fixed Speed

 

 

ET0010A

ET0100A / ET1000A

All ETEPs

1000 Mbps Half-duplex

3

 

 

 

 

 

 

 

On the local and remote ports, the ETEPs support the speeds shown in Table 86.

Table 86 Link speeds on the local and remote ports

Link speed

Auto-negotiate

Fixed Speed

Fixed Speed

 

 

 

All ETEPs

ET0010A / ET0100A

ET1000A

10

Mbps Half-duplex

3

3

 

 

 

 

 

 

10

Mbps Full-duplex

3

3

 

 

 

 

 

 

100

Mbps Half-duplex

3

3

 

 

 

 

 

 

100

Mbps Full-duplex

3

3

 

 

 

 

 

1000 Mbps Full-duplex

3

 

3

 

 

 

 

 

 

NOTE

If you are using copper SFP transceivers, auto-negotiation must be enabled on the ET1000A and on the device that the ET1000A is connecting to. The recommended copper SFP transceivers negotiate only to

1 Gbps, even though they advertise other speeds. See the ETEP Release Notes for a list of recommended transceivers.

Remote and Local Port Settings

The remote port connects the ETEP to an untrusted network, which is typically a WAN, campus LAN, or MAN. The local port connects the ETEP to a device on the local, trusted side of the network, such as a server or a switch.

See the following topics for configuration details:

“Auto-negotiation - All Ports” on page 305

“Transparent Mode” on page 306

“Local and Remote Port IP Addresses” on page 307

“Transmitter Enable” on page 308

“DHCP Relay IP Address” on page 309

“Ignore DF Bit” on page 310

“Reassembly Mode” on page 310

Transparent Mode

Transparent mode is the ETEP’s default mode of operation on the local and remote ports. It is appropriate for Layer 2 policies and for most distributed key policies. When operating in transparent mode the ETEP

306

EncrypTight User Guide

Image 305
Contents EncrypTight User Guide Table of Contents Managing EncrypTight Users Provisioning Appliances Getting Started with EtemsManaging Appliances 117 Managing IP Networks Managing Key Management SystemsManaging Network Sets Creating Vlan ID Ranges for Layer 2 NetworksPolicy Design Examples 211 Modifying the Etkms Properties File Using Enhanced Security FeaturesEtep Configuration 299 302 Index 343 About This Document PrefaceContacting Black Box Technical Support Part I EncrypTight Installation and Maintenance EncrypTight User Guide Distributed Key Topologies EncrypTight OverviewTopology Description Network topologiesLayer 3 IP topologies Layer 2 Ethernet topologiesRelated topics EncrypTight ElementsKey Management System EncrypTight Element Management SystemPolicy Manager Single Etkms for multiple sites Policy Enforcement PointShared keys Point-to-Point Negotiated TopologyLayer 2 Point-to-Point Deployment Security within EncrypTightSecure Key Storage within the Etkms Secure Communications Between DevicesEncrypTight Component Connections EncrypTight Deployment PlanningEtpm to Etkms Connections Management Station ConnectionsEtpm and Etkms in Layer 3 IP Policies Etpm and Etkms on the Same SubnetworkEtpm and Etkms on Different Subnetworks Out-of-band Etkms management in an Ethernet network External Etkms to Etkms Connections Connections for Backup ETKMSsEtkms to Etkms Connections in Ethernet Networks Connecting Multiple ETKMSs in an IP NetworkEtkms to PEP Connections in IP Networks Etkms to PEP ConnectionsIn-line Etkms to PEP communications in IP networks Etkms to PEP Connections in Ethernet NetworksIPv6 Address Support Network Clock SynchronizationAddress Format Address Representation Certificate SupportIPv6 address representations Addressing Method Description Network Addressing for IP NetworksNetwork Addressing Options Related topics Before You Start Installation and ConfigurationSoftware Requirements Hardware RequirementsEncrypTight management station requirements Third party management station softwareInstalling EncrypTight Software for the First Time EncrypTight Software InstallationTo install the EncrypTight software Firewall PortsTo uninstall EncrypTight Uninstalling EncrypTight SoftwareUpgrading to a New Version of EncrypTight Starting EncrypTightExiting EncrypTight Management Station ConfigurationTo start Etems Related topicSecuring the Management Interface To enable the Microsoft FTP Server serviceEnabling the Microsoft FTP Server Etems communications optionsConfiguring ETKMSs Installing ETKMSsConfiguring the Syslog Server Etkms server connectionsAdding a Local Etkms Basic Configuration for Local ETKMSsAbout Local ETKMSs Starting the Local Etkms Automatically Launching and Stopping a Local EtkmsTo add a local Etkms To launch a local EtkmsPrior to configuring the batch file do the following Configuring External ETKMSsTo configure the batch file Maintaining the start.bat fileTo change the admin password Changing the Admin PasswordLogging Into the Etkms To log into the EtkmsTo change the root password Changing the Root PasswordTo configure the network connection and hostname Configure the Network ConnectionStatic IP Netmask Default Gateway IP address IPv4To set the hostname and IPv6 default gateway address To configure the network interfaceTo set the default DNS server and configure the hosts file IPv6To set the time zone Configure Time and Date PropertiesTo set up time synchronization To restart the NTP daemon Ntpq -p command outputTo check the time source connection status Field DescriptionCheck the Status of the Hardware Security Module Starting and Stopping the Etkms ServiceTo check the status of the Etkms service Configuring Syslog Reporting on the ETKMSsTo configure syslog reporting on a Etkms Checking the Status of the EtkmsPolicy Enforcement Point Configuration Passwords to change Default User Accounts and PasswordsManaging Licenses Etep Throughput SpeedsTo install a license on the Etep Installing LicensesTo enter EncrypTight licenses Choose Tools Put LicenseUpgrading Licenses Next StepsUpgrading the EncrypTight License Upgrading Etep LicensesNext Steps Installation and Configuration EncrypTight User Guide Working with EncrypTight User Accounts Managing EncrypTight UsersEncrypTight account types and privileges Configuring EncrypTight User AuthenticationTask Administrator User Common Access Card Authentication Password Authentication and ExpirationLogin Session Inactivity Timer DoD Login Banner EncrypTight user name and password conventions Login preferences default settingsPreference Setting Parameter User Name PasswordTo change a password Changing an EncrypTight User PasswordTo add an EncrypTight user account To modify an EncrypTight user accountExample 2 Setting up new EncrypTight and Etep users Example 1 Default EncrypTight user and default Etep userHow EncrypTight Users Work with Etep Users Relationship between EncrypTight users and Etep usersExample 3 Adding a new Etep user to EncrypTight About the EncrypTight Workspace Maintenance TasksWorking with the EncrypTight Workspace On the File menu, click Save Workspace To Saving a Workspace to a New LocationTo save a workspace to a new location To load an existing workspace Loading an Existing WorkspaceDeleting a Workspace Moving a Workspace to a New PCTo move a workspace to a new PC To delete a workspaceSchedule the Upgrade Installing Software UpdatesVerify Etkms Status and Deploy Policies Upgrade the EncrypTight SoftwarePrepare Etpm Status and Renew Keys To deploy policies Upgrade PEP SoftwareFTP server site information for appliance software upgrades To upgrade software on the PEPsOn the Tools menu, click Upgrade Software Change the PEP Software Version and Check Status Click Edit Multiple Configurations Software VersionTo change the software version of the PEPs To check the status of the PEPsTo stop and remove the current Etkms software Return Status Refresh and Key Renewal to Original SettingsUpgrading External ETKMSs To configure the new Etkms software To install the new Etkms softwareTo mount the Cdrom drive To start the Etkms softwareMaintenance Tasks EncrypTight User Guide Etems Part II Working with Appliances usingEncrypTight User Guide Etems Quick Tour Defining Appliance ConfigurationsGetting Started with Etems Interface configuration for a new ET1000A appliance Pushing Configurations to AppliancesUpgrading Appliance Software Comparing ConfigurationsMaintenance and Troubleshooting Policy and Certificate Support Understanding the Etems WorkbenchEditors Appliance Manager perspective ViewsPerspectives ToolbarsTo open a perspective Etems toolbarCertificate Manager toolbar Status IndicatorsAppliance Manager toolbar Status Indicator Description Appliance status indicatorsUnderstanding Roles EncrypTight User TypesModifying Communication Preferences Function Administrator OpsAppliance roles for ETEPs To change communication preferencesPreference Description Strict authentication communication preferencesGeneral communication preferences Enable Certificate Ignore CRL accessCRL File Location Policy ExtensionsProvisioning Basics Provisioning AppliancesNew Appliance editor for the ET1000A To add a new appliance Adding a New ApplianceSaving appliance configurations Saving an Appliance ConfigurationTo push Etems configurations to appliances On the Tools menu, click Put ConfigurationsResult Description Put configuration statusViewing Appliance Status Appliances view To configure automatic status checkingEtems To apply a filter to the appliances in the Appliances view Filtering Appliances Based on AddressTo reboot appliances Rebooting AppliancesAppliance User Management Etep User RolesDefault user names and passwords on the Etep Configuring the Password Enforcement PolicyRole Default user name Default password Appliance roles for ETEPs v 1.4 and laterUser Name Conventions Default Password Policy ConventionsStrong Password Policy Conventions Upgrading Software Removing ETEPs From ServiceAdding Etep Users Managing Appliance UsersTo add a user to the Etep On the Tools menu, click Appliance User Add UserDefault password Strong password Parameter Policy Password policy valuesDeleting Etep Users Modifying Etep User CredentialsTo modify Etep user credentials On the Tools menu, click Appliance User Modify UserOn the Tools menu, click Appliance User Delete User Viewing Etep UsersTo delete a user from the Etep Customizing the Default Configuration Working with Default ConfigurationsTo customize the default configuration On the Edit menu, click Default ConfigurationTo return the default values to factory settings Restoring the Etems Default ConfigurationsOn the Edit menu, click Default Configurations Provisioning Large Numbers of AppliancesImporting Configurations from a CSV File Creating a Configuration TemplateAttribute Description To import appliance configurations to EtemsRemote and local keywords and attributes Importing Remote and Local Interface AddressesChanging Configuration Import Preferences Checking the Time on New Appliances Shutting Down AppliancesShutdown operational codes To shut down the EtepManaging Appliances Editing ConfigurationsTo change the management IP address on the appliance Changing the Management IP AddressChanging the Address on the Appliance Change Management IP window Related topics Changing the Address in EtemsOperation failed message in response to management IP change Changing the Date and TimeChanging Settings on Multiple Appliances Changing Settings on a Single ApplianceTo edit the configuration of a single appliance To change the date and timeDeleting Appliances To update an appliance setting on multiple appliancesConnecting to the Command Line Interface Connecting Directly to an ApplianceUpgrading Appliance Software To delete appliances124 EncrypTight User Guide To upgrade software 126 EncrypTight User Guide Canceling an Upgrade Restoring the Backup File SystemWhat to do if an Upgrade is Interrupted Checking Upgrade StatusTo restore the appliance file system from a backup copy Part III Using Etpm to Create Distributed Key Policies 130 EncrypTight User Guide Opening Etpm Getting Started with EtpmAbout the Etpm User Interface To open EtpmEtpm perspective Component Chapter EncrypTight Components ViewEditors Status indicators Etpm Status IndicatorsPolicy View To edit an element from the policy viewSorting and Using Drag and Drop Etpm Toolbar To enable or disable automatic status checkingEtpm Status Refresh Interval Etpm toolbarEthernet Policies About Etpm PoliciesIP Policies Policy generation and distribution Policy Generation and DistributionKey generation with one Etkms Key generation with multiple ETKMSs Creating a Policy An OverviewNetwork B Network aNetwork Set a Network Set BTo create a policy 144 EncrypTight User Guide EncrypTight User Guide 145 146 EncrypTight User Guide Provisioning PEPs Managing Policy Enforcement PointsAdding a New PEP in Etems EncrypTight PEP configurationConfiguration Description On the Advanced tab, select Enable Sntp Client On the Features tab, select Enable passing TLS trafficAdding Large Numbers of PEPs Adding a New PEP Using EtpmTo add a new PEP using Etpm To push Etems configurations to PEPs Pushing the ConfigurationTo edit a PEP’s configuration Editing PEPsSelect Edit Multiple Configurations Sntp Client To change the NTP settings for multiple PEPsEditing Multiple PEPs Editing PEPs From EtpmChanging the IP Address of a PEP Deleting PEPsChanging the PEP from Layer 3 to Layer 2 Encryption To change the IP address of a PEPTo delete PEPs Etkms connections Managing Key Management SystemsTo add an Etkms Adding ETKMSsDeleting ETKMSs Editing ETKMSsEtkms entries To edit an existing EtkmsTo delete an existing Etkms Adding Networks Managing IP NetworksNetwork entries To add a networkNetwork IP Address Network MaskGrouping Networks into Supernets Advanced Uses for Networks in PoliciesUsing Non-contiguous Network Masks IP Address Network Mask Networks definitionsTo edit an existing network Editing NetworksDeleting Networks To delete a network Managing IP Networks 166 EncrypTight User Guide Network Sets Managing Network SetsIP address Mask 40.55.11.0 255.255.255.0 Types of Network SetsIP address Mask 40.32.21.0 255.255.255.0 IP address Mask Network set for a collection of networksNetwork Set fields Adding a Network SetTo add a Network Set System Key ManagementNetwork Addressing ModeNetwork Set editor Importing Networks and Network SetsNetworks and network sets import document format in Excel Deleting a Network Set Editing a Network SetTo import networks and network sets into Etpm To edit a Network SetTo delete an existing network set Managing Network Sets 176 EncrypTight User Guide To add a new Vlan ID Range Creating Vlan ID Ranges for Layer 2 NetworksAdding a Vlan ID Range Upper Vlan ID Vlan ID range entriesLower Vlan ID Deleting a Vlan ID Range Editing a Vlan ID RangeTo edit a Vlan ID range To delete an existing Vlan ID range180 EncrypTight User Guide Policy Concepts Creating Distributed Key PoliciesSchedule for Renewing Keys and Refreshing Policy Lifetime Policy PriorityLayer 2 Ethernet payload encryption Policy Types and Encryption MethodsEncapsulation To use Aria in an encryption policy, do the following Encryption and Authentication AlgorithmsAria Encryption Key Generation and ETKMSs Addressing ModeUsing Encrypt All Policies with Exceptions Policy Policy Type Priority Action Protocol Covered Policy Size and Etep Operational LimitsEncrypt all policy with exceptions Minimizing Policy Size To add a new Layer 2 mesh policy Adding Layer 2 Ethernet PoliciesLayer 2 Mesh policy entries Layer 2 Mesh policy editor Adding a Hub and Spoke Policy Adding Layer 3 IP PoliciesHub and spoke policy entries To add a new hub and spoke policyAddressing IPSecMinimize Policy SizeHub and spoke policy editor To add a new mesh policy Adding a Mesh PolicyMesh policy entries Specifies a method for reducing the policy size Mesh policy editor Multicast network example Adding a Multicast PolicyMulticast policy entries To add a multicast policyNetwork MulticastMulticast policy editor To add a point-to-point policy Adding a Point-to-point PolicyPoint-to-point policy entries Network Set Point aPoint a Ports Point BPoint-to-point policy editor Adding Layer 4 PoliciesTo create a new Layer 4 policy Policy DeploymentVerifying Policy Rules Before Deployment To enable or disable the deployment warning Setting Deployment Confirmation PreferencesDeploying Policies To verify policiesDeleting Policies Editing a PolicyTo edit an existing policy Editing policiesSelect Tools Clear Policies To delete an existing policyTo delete all policies Basic Layer 2 Point-to-Point Policy Example Policy Design ExamplesPoint-to-point Layer 2 encryption policy Layer 2 Ethernet Policy Using Vlan IDsSetting PEP Policy 3 Discard All Other Policy 2 Partner and Partner Portal ServerEncrypt Traffic Between Regional Centers Complex Layer 3 Policy ExampleEncrypt all mesh policy Encrypt Traffic Between Regional Centers and BranchesNetwork sets for mesh policy Region a hub and spoke policy Network sets for the hub and spoke policiesRegion C hub and spoke policy Region B hub and spoke policyRegion D hub and spoke policy FieldPass protocol 88 in the clear mesh policy Passing Routing ProtocolsEncrypTight User Guide 219 Policy Design Examples 220 EncrypTight User Guide Part IV Troubleshooting 222 EncrypTight User Guide Possible Problems and Solutions Etems TroubleshootingConfig to Appliance Symptom Explanation and possible solutionsAppliance Unreachable PreferencesDisable-trusted-hosts CLI command Appliance ConfigurationCompare Config to Appliance . Do one of the following Pushing ConfigurationsAppliance Tools Reboot About upgrades show system-log and show upgrade Status Software UpgradesPinging the Management Port To ping the management portRetrieving Appliance Log Files Tools preferences To change the default ping toolFTP server site information for log retrieval To retrieve log files from an applianceOn the Tools menu, click Retrieve Appliance Logs Viewing Statistics Viewing Diagnostic DataStatistic Description Etep StatisticsExporting SAD and SPD Files Viewing Port and Discard StatusTo access the appliance CLI CLI Diagnostic CommandsTo view the log information Working with the Application LogViewing the Application Log from within EncrypTight Exporting the Application Log Setting Log FiltersSending Application Log Events to a Syslog Server Icon Description Other Application Log ActionsLog File Actions Monitoring Status Etpm and Etkms TroubleshootingLearning About Problems Etpm status problems and solutions Symptoms and SolutionsEtep PEPs, see the EncrypTight User Guide Policy ErrorsRenew Key Errors Status ErrorsEtkms Log Files Viewing Log FilesEtpm Log Files Linux Commands Etkms Troubleshooting ToolsCommand Description Etkms Server OperationResetting the Admin Password PEP Troubleshooting ToolsOptimizing Time Synchronization Shutting Down or Restarting an External EtkmsStatistics To disable the Sntp client on multiple PEPsEtep PEP Policy and Key Information To view statisticsReplacing Licensed ETEPs Troubleshooting PoliciesChecking Traffic and Encryption Statistics To export SAD or SPD files from Etep PEPsViewing Policies on a PEP Solving Policy ProblemsPlacing PEPs in Bypass Mode Expired Policies Allowing Local Site Exceptions to Distributed Key PoliciesCannot Add a Network Set to a Policy Solving Network Connectivity ProblemsCannot Communicate with PEP Certificate Implementation ErrorsModifying EncrypTight Timing Parameters Invalid Parameter in Function Call Etkms Boot ErrorInvalid Certificate Error Enter strict-client-authentication disable To disable strict authentication on ETEPsEtpm and Etkms Troubleshooting 252 EncrypTight User Guide Part V Reference 254 EncrypTight User Guide About the Etkms Properties File Modifying the Etkms Properties FileLogging Setup Hardware Security Module ConfigurationDigital Certificate Configuration Peer Etkms and Etpm Communications Timing Base Directory for Storing Operational State DataPEP Communications Timing Policy Refresh TimingPEP Communications Timing Page About Enhanced Security Features Using Enhanced Security FeaturesAbout Strict Authentication How to Reference Prerequisites for Using Certificates with EncrypTightPrerequisites Order of OperationsDistinguished name information Setting DescriptionCertificate Information Usage, you type this string as follows Using Certificates in an EncrypTight SystemChanging the EncrypTight Keystore Password Changing the Keystore PasswordChanging the Etkms Keystore Password To change the EncrypTight keystore passwordChanging the Keystore Password on a Etkms Changing the Password Used in the Etkms Properties File Changing the Keystore Password on a Etkms with an HSMTo change the password listed in the Etkms properties file Restart the Etkms Service To start the Etkms serviceClick Enable Policy Extensions Configuring the Certificate Policies ExtensionTo configure the certificate policies extension for ETEPs Click Enable Certificate Policy Extensions To configure certificate policy extensions for ETKMSsEtkms Certificate Policies Entries Parameter DescriptionEncrypTight User Guide 271 Generating a Key Pair Working with Certificates for EncrypTight and the ETKMSsRequesting a Certificate Keytool genkeypair CommandTo generate a key pair To create the certificate requestImporting a CA Certificate To install a CA certificateImporting a CA Certificate Reply Keytool Parameters for Importing a CA CertificateExporting a Certificate Configuring the HSM for KeytoolWorking with Certificates and an HSM Generating a Key Pair for use with the HSM Importing CA Certificates into the HSMImporting Signed Certificates into the HSM Working with Certificates for the ETEPsGenerating a Certificate Signing Request for the HSM To start the Certificate Manager do one of the following Understanding the Certificate Manager PerspectiveObtaining External Certificates Certificate Manager WorkflowWorking with External Certificates To obtain a CA certificate from a CA Installing an External CertificateTo install an external certificate Requesting a Certificate Working with Certificate Requests282 EncrypTight User Guide Viewing a Pending Certificate Request Installing a Signed CertificateCertificate usage To view a pending certificate signing requestSetting Certificate Request Preferences Canceling a Pending Certificate RequestTo cancel a pending certificate request To set certificate request preferencesCertificate request preference fields Managing Installed CertificatesExporting a Certificate To export an installed certificateViewing a Certificate Validating Certificates Validating Certificates Using CRLsDeleting a Certificate To delete an external certificateConfiguring CRL Usage on ETEPs Configuring CRL Usage in EncrypTight and the ETKMSsTo use CRLs with the EncrypTight software To use CRLs with the EtkmsTo install a CRL on the Etep Validating Certificates Using OcspHandling Revocation Check Failures To view CRLsClick Enable Online Certificate Status Protocol Ocsp To set up Ocsp in EncrypTightEncrypTight Ocsp Options Options DescriptionTo set up Ocsp on the ETEPs To set up Ocsp in the EtkmsClick Enable Ocsp Ocsp SettingsTo enable strict authentication in the EncrypTight software Enabling and Disabling Strict AuthenticationTo enable strict authentication on the Etkms To enable strict authentication on PEPsClear the Enable Strict Client Authentication box To disable strict authenticationTo disable strict authentication from the command line Removing CertificatesSelect Tools Clear Certificates Using a Common Access CardTo remove certificates To add common names to the Etkms Configuring User Accounts for Use With Common Access CardsEnabling Common Access Card Authentication Click XML-RPC Certificate Authentication To enable CAC Authentication on the EtepTo enable CAC Authentication on the Etkms To enable CAC Authentication in EncrypTightHandling Common Name Lookup Failures To specify how to handle common name failuresUsing Enhanced Security Features 298 EncrypTight User Guide Etep Configuration Appliance Name Identifying an ApplianceProduct Family and Software Version Throughput Speed Interface ConfigurationTo configure appliance interfaces Management Port Addressing ET0100A interfaces configuration Related topicsIPv4 management port addressing IPv4 AddressingIPv6 management port addressing IPv6 AddressingLink speeds on the management port Auto-negotiation All PortsLink speeds on the local and remote ports Remote and Local Port SettingsTransparent Mode Local and Remote Port IP Addresses When to use transparent modePolicy Type Mode of operation IP Address and Subnet Mask Transmitter EnableDefault Gateway Dhcp Relay IP Address Transmitter Enable settings on the EtepIgnore DF Bit settings Reassembly ModeReassembly mode settings Ignore DF BitTrusted host list Trusted HostsTo add a trusted host Inbound trusted host protocols used by EncrypTightProtocol Outbound host Appliance Editor TabSystem Information Snmp ConfigurationSnmp system information Community StringsTo define a community name Under Community Strings, click AddTrap Description TrapsTraps reported on the Etep SNMPv3 To configure a trap hostSNMPv2 Trap Hosts SNMPv3 Configuration Related topics To retrieve engine IDs Generating the Engine IDRetrieving and Exporting Engine IDs Viewing SNMPv3 Engine IDs Related topics Configuring the SNMPv3 Trap Host UsersSNMPv3 trap host users SNMPv3 Trap Host configuration To configure a trap host userEtep Logging tab Logging ConfigurationFacility Description Log Event SettingsLog facilities Log priorities Defining Syslog ServersTo define a syslog server Under Syslog Servers, click AddLog file sizes Log File ManagementLog name File size Internals logsLog files extracted from the Etep Related topics Advanced ConfigurationValid Pmtu ranges on Etep appliances Path Maximum Transmission UnitPmtu and fragmentation behavior on the Etep Packet Payload Size Layer 2 Etep Layer 3 EtepPassword Strength Policy CLI Inactivity TimerNon IP traffic handling configuration Non IP Traffic HandlingXML-RPC Certificate Authentication Sntp Client Settings SSH Access to the EtepTo configure the NTP client IKE Vlan TagsOcsp Settings Features ConfigurationCertificate Policy Extensions IKE Vlan TagsEnabling Fips Mode Fips ModeFips approved encryption and authentication algorithms Encryption algorithms Authentication algorithmsDisabling Fips Policy Type Action upon entering Fips modeVerifying Fips Status on the Etep Operational NotesSetting Definition EncrypTight SettingsEncrypTight settings Working with Policies Encryption Policy SettingsEncryption policy settings To launch Etpm from Etems Using EncrypTight Distributed Key PoliciesCreating Layer 2 Point-to-Point Policies Etep Policy tab Selecting a Role Using Preshared Keys for IKE AuthenticationUsing Group IDs How the Etep Encrypts and Authenticates Traffic Selecting the Traffic Handling ModeIKE Phase 2 Parameters Parameter ValueInterfaces defaults Factory DefaultsInterfaces Default Setting InterfacesTrusted Hosts Trusted hosts defaultsSnmp defaults Advanced LoggingPolicy Hard-coded Settings FeaturesFeatures defaults Features Default SettingNumerics IndexIndex EncrypTight User Guide 345 Etpm See also HSM Https TLS 348 EncrypTight User Guide EncrypTight User Guide 349 350 EncrypTight User Guide See also TLS trap configuration 352 EncrypTight User Guide Black Box Tech Support FREE! Live /7
Related manuals
Manual 48 pages 53.09 Kb Manual 88 pages 24.35 Kb

EncrypTight, ET0100A, ET0010A, ET1000A specifications

The Black Box ET1000A, ET0010A, EncrypTight, and ET0100A are advanced solutions designed for secure data transmission and network management, catering to modern enterprise needs. These tools integrate cutting-edge technologies to enhance connectivity, security, and efficiency within various environments.

The Black Box ET1000A is primarily a high-performance Ethernet over Twisted Pair (EoTP) solution. It enables users to extend Ethernet signals over long distances using existing twisted-pair cabling without sacrificing speed or reliability. With support for speeds up to 100 Mbps, this device is ideal for organizations looking to upgrade their existing infrastructure without extensive rewiring. Key features include plug-and-play installation, which simplifies deployment, and versatile compatibility with both legacy and modern ethernet networks.

The ET0010A model takes connectivity a step further by providing seamless integration with fiber optics. This device supports transmission distances that far exceed traditional copper solutions, making it a perfect fit for larger facilities or multi-building campuses. Its built-in Ethernet switch enhances network efficiency by providing multiple ports for device connectivity, thus facilitating greater data flow.

EncrypTight technology is a notable feature across these Black Box models, offering advanced encryption capabilities to safeguard sensitive data during transmission. With military-grade encryption protocols, EncrypTight ensures that corporate information remains secure from potential eavesdroppers. This technology is essential for businesses operating in regulated industries or that handle confidential customer information.

The ET0100A model combines intelligence with monitoring features to provide users with comprehensive network insights. It boasts built-in diagnostic tools that enable IT professionals to troubleshoot issues quickly and efficiently. Additionally, it features real-time performance monitoring, allowing users to analyze bandwidth usage and optimize network performance accordingly.

In conclusion, the Black Box ET1000A, ET0010A, EncrypTight, and ET0100A are powerful tools that embody the latest in data transmission and network management technologies. With their unique features—including extended connectivity capabilities, robust encryption technologies, and real-time monitoring solutions—these devices cater to the growing demands of businesses seeking to enhance their network infrastructure while ensuring robust security and efficiency. Integrating these tools into any organization’s operations can fundamentally improve both performance and data protection, making them indispensable in today’s digital landscape.