Black Box ET1000A, ET0010A, EncrypTight Network set for a collection of networks, IP address Mask

Models: EncrypTight ET0100A ET0010A ET1000A

1 352
Download 352 pages 21.02 Kb
Page 168
Image 168

Types of Network Sets

Figure 61 Network set for a collection of networks

Figure 61 illustrates a network set comprised of two networks and two PEPs. In ETPM, this network set includes both PEP 1 and PEP 2, and both network IP addresses and masks.

IP address

Mask

30.25.11.0

255.255.255.0

30.24.3.0

255.255.255.0

Figure 62 Network set that does not include a PEP

A network set does not have to include any PEPs. This is useful if you have PEPs that are encrypting traffic between two routers that need to exchange routing protocols. If the PEPs are encrypting all traffic, the routers cannot see the information in the routing packets. To allow the routers to exchange routing information create a clear policy for the routing protocol, for example OSPF (protocol 89). Create one network set with a wildcarded network (0.0.0.0) that includes PEP 1 and PEP 2. Create a second network set with a wildcarded network (0.0.0.0), but without any PEPs. Then using these two network sets, you can create a point-to-point policy that passes protocol 89 packets in the clear.

EncrypTight User Guide

169

Page 168
Image 168
Black Box ET1000A, ET0010A, EncrypTight, ET0100A manual Network set for a collection of networks, IP address Mask