HP-UX IPSec and MC/ServiceGuard

Step 2: Configuring HP-UX Host IPSec Policies for MC/ServiceGuard

Specify the following values for the remaining filter fields in the host

IPSec policies:

Protocol: ALL

Source and destination ports: 0 (all ports)

For the cluster shown in Figure 8-1 on page 237, one way to configure PASS host ipsec policies for the heartbeat address pairs is to configure six host ipsec policies with the following filter specifications:

Source IPDestination

 

Source

Destination

Address/IP Address/

Protocol

Port

Port

Prefix

Prefix

 

 

 

 

 

 

 

 

 

10.0.0.0/8

10.1.1.1/32

ALL

0

0

 

 

 

 

 

10.0.0.0/8

10.2.2.2/32

ALL

0

0

 

 

 

 

 

10.0.0.0/8

10.3.3.3/32

ALL

0

0

 

 

 

 

 

15.0.0.0/8

15.1.1.1/32

ALL

0

0

 

 

 

 

 

15.0.0.0/8

15.2.2.2/32

ALL

0

0

 

 

 

 

 

15.0.0.0/8

15.3.3.3/32

ALL

0

0

 

 

 

 

 

CAUTION

Use caution when configuring “open” host ipsec policies (policies that

 

allow all or most packets to pass in clear text). For more information, see

 

“Maximizing Security” on page 59.

 

 

Private Dedicated Heartbeat Networks

If you are using a dedicated heartbeat network that is also a private network, you can simplify your configuration by replacing the heartbeat address filters in the private network with one host IPSec policy for the

246

Chapter 8