HP-UX IPSec and MC/ServiceGuard

Step 2: Configuring HP-UX Host IPSec Policies for MC/ServiceGuard

packets listed below, however, HP recommends that you do not allow the packets to pass in clear text. For more information, see “Maximizing Security” on page 59.

Source IP

Destination

Protocol

Source

Destination

Address

IP Address

Port

Port

 

 

 

 

 

 

remote

cluster node

TCP

0

0

command

address

 

 

 

client address

 

 

 

 

(or wildcard)

 

 

 

 

 

 

 

 

 

For remote execution of the cmscancl command, HP-UX IPSec must not discard the following packets:

Source IP

Destination

Protocol

Source

Destination

Address

IP Address

Port

Port

 

 

 

 

 

 

remote

cluster node

TCP

0

514

command

address

 

 

 

client address

 

 

 

 

(or wildcard)

 

 

 

 

 

 

 

 

 

Configuring Host IPSec Policies for ServiceGuard Manager

If you using ServiceGuard Manager, you must configure HP-UX IPSec so it does not discard SNMP traffic between cluster nodes and the ServiceGuard Manager system. Configure HP-UX IPSec so it does not discard packets listed in the sections below.

Chapter 8

251