HP-UX IPSec and MC/ServiceGuard

Step 2: Configuring HP-UX Host IPSec Policies for MC/ServiceGuard

Cluster Node Host IPSec Policies for ServiceGuard Manager

For each cluster node, configure host IPSec policies so HP-UX IPSec does not discard (the transform list contains any transform except DISCARD) the packets listed below. If HP-UX IPSec is not installed on the ServiceGuard Manager system, configure PASS host IPSec policies for these packets.

Source IP

Destination

Protocol

Source

Destination

Address

IP Address

Port

Port

 

 

 

 

 

 

cluster node

ServiceGuard

UDP

161

0

address (or

Manager

 

 

 

wildcard)

address

 

 

 

 

 

 

 

 

cluster node

ServiceGuard

UDP

0

162

address (or

Manager

 

 

 

wildcard)

address

 

 

 

 

 

 

 

 

ServiceGuard Manager Host IPSec Policies

If HP-UX IPSec is installed on the ServiceGuard Manager system, configure host IPSec policies for the packets listed below with a transform list that corresponds to the policies on the cluster nodes.

Source IP

Destination

Protoco

Source

Destination

Address

IP Address

l

Port

Port

 

 

 

 

 

ServiceGuard

cluster node

UDP

0

161

Manager

address

 

 

 

address (or

 

 

 

 

wildcard)

 

 

 

 

 

 

 

 

 

ServiceGuard

cluster node

UDP

162

0

Manager

address

 

 

 

address (or

 

 

 

 

wildcard0)

 

 

 

 

 

 

 

 

 

252

Chapter 8