Site-to-Site Policies

   

In a site-to-site deployment, IPSec gateways protect traffic for networks behind them, that is traffic that originates on a protected network behind one IPSec gateway and is destined for the protected network behind another IPSec gateway. Each traffic flow requiring IPSec protection requires a separate policy statement, even if different flows go to the same peer.

The flow to be protected is identified by a selector and that selector is installed in the SPD. Associated with the selector is an IP address of the peer with whom the IPSec connection is to be made to protect the flow.

With site-to-site deployments peers have mirror images of each other's policy from gateway A's point of view traffic is from A's network to B's network and B is the peer, while from B's point of view traffic is from B's network to A's network and A is the peer.


   
Top


IPSec(c) The New Security Standard for the Internet, Intranets, and Virtual Private Networks
IPSec (2nd Edition)
ISBN: 013046189X
EAN: 2147483647
Year: 2004
Pages: 76

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net