
Configuring IP Services
2-16
Configuring the Revised IP Security Option
IP routers support the Department of Defense (DoD) Revised IP Security Option
(RIPSO), as defined in RFC 1108 on a per-interface basis. While RIPSO RFC
1108 specifies both “basic” and “extended” security options, our implementation
supports only the basic option.
RIPSO is a feature that allows end systems and intermediate systems (routers) to
add labels to or process security labels in IP datagrams that they transmit or
receive on an IP network. The labels specify security classifications (for example,
Top Secret, Secret, Confidential, and Unclassified, in descending order), which
can be used to limit the devices that can access these labeled IP datagrams.
As a labeled IP datagram traverses an IP network, only those systems that have the
proper clearance (that is, whose security classification range covers the
classification specified by the datagram) should accept and forward the datagram.
Any system whose security classification range does not cover the classification
specified by the security label should drop the datagram.
Note: RIPSO does not include any method of preventing a system that does
not support RIPSO from simply accepting and forwarding labeled datagrams.
Thus, in order for RIPSO to be effective, all systems in a network must support
RIPSO and process IP datagrams as described.
For instructions on using Site Manager to enable RIPSO support on an IP interface, see
the Enable Security parameter on page 2-49. For complete information on RIPSO
parameters, see “Configuring RIPSO Support” on page 2-76.
Komentáře k této Příručce