Black Box ET1000A, ET0010A, EncrypTight Troubleshooting Policies, Replacing Licensed ETEPs, Tip

Models: EncrypTight ET0100A ET0010A ET1000A

1 352
Download 352 pages 21.02 Kb
Page 244
Image 244

Troubleshooting Policies

deployed to the PEP, including the destination and source IP addresses, priority, and the policy type. The SAD includes information on every security association (SA) established between the ETEP PEP and another appliance.

You can use this information to help you troubleshoot policy problems involving ETEP PEPs. You can use ETEMS to export the SPD and SAD to CSV files.

To export SAD or SPD files from ETEP PEPs:

1In the Appliance Manager, select the target ETEP PEP in the Appliances view.

2Click View > Statistics.

3In the upper right corner of the Statistics view, click the Export button. From the list, choose which file to export (SAD or SPD).

4You will be prompted to save the .csv file. Browse to a location on your hard drive and click Save.

5To open the .csv file, click Yes when prompted. Windows opens the file with whatever application is associated with the .csv file extension. Click No to complete the operation and without viewing the file.

TIP

The .csv files can be easier to read and work with if you import them into a spreadsheet application such as Microsoft Excel.

Related topic:

“Exporting SAD and SPD Files” on page 232

Replacing Licensed ETEPs

In the event that you need to replace an ETEP with software version 1.6 and later, you must generate and install a new license on the replacement before you can use it. For instructions on how to install licenses, see “Managing Licenses” on page 56.

Troubleshooting Policies

Many problems with encryption and policies can be solved by changing the priorities assigned to the policies. If the policy priorities are not correctly assigned, traffic can be dropped or mistakenly sent in the clear. To troubleshoot these issues, first check to see if traffic is being passed or encrypted.

“Checking Traffic and Encryption Statistics” on page 245

“Solving Policy Problems” on page 246

Checking Traffic and Encryption Statistics

To check if traffic is being passed or encrypted using the Statistics view:

1In the Appliances view, click the target PEP to select it.

2Click View > Statistics.

EncrypTight User Guide

245

Page 244
Image 244
Black Box ET1000A Troubleshooting Policies, Replacing Licensed ETEPs, Checking Traffic and Encryption Statistics, Tip