User's Manual

Table Of Contents
Fortress ES-Series CLI Guide: Network Security, Authentication and Auditing
134
2 SPD entries registered
Use show with the
-name
flag to display only the specified SPD
entry, or with
-all
to show the complete list of configured
SPDs.
The
-dynamicpeers
flag permits you to display only IPsec peers
connected through dynamic endpoint SPDs (refer to Section
4.4.3, below).
To display just the total number of SPDs on the Mesh Point,
use
show with the
-counter
flag:
# show spd -counter
2 SPD entries registered
To delete IPsec SPD entries:
# del spd -all|-name
<SPDname>
Deleted SPD entries are removed from the show spd output.
4.4.3 Dynamic Endpoints for IPsec
When IPsec is globally enabled and configured on the Mesh
Point, SPD (Security Policy Database) rules can be used to
define dynamic endpoints for IPsec SAs.
NOTE: If L2TP is
disabled, IPsec
dynamic endpoints can
be used simultaneously
for FP Mesh WDS and
VPN client connections.
Dynamic endpoint SPDs configured on the Mesh Point are
intended to permit IPsec SAs to be dynamically created for one
of two types of connection:
FastPath Mesh network WDS (wireless distribution system)
bridging links
VPN (virtual private network) client connections, from LAC
(L2TP Access Concentrator) clients
NOTE:
SPD entries
specifying static
IPsec peer IP addresses,
as described in Section
4.4.2, can coexist with
dynamic SPDs.
SPD rules for dynamic endpoints are created in Mesh Point UIs
with existing IPsec
spd controls by specifying
0.0.0.0
—to
indicate any IP address—for the appropriate SPD entry
parameters.
Dynamic SPD rules are implemented along with and in the
same manner as any static SPD entries present in the Mesh
Point IPsec configuration: Packets incoming on the associated
interface are compared against each SPD entry’s
Remote traffic
selector, and when the IP subnet from which the packet
originated matches, the rule’s
Action is applied. Outgoing
packets are handled in the same way, except that an SPD
rule’s application is triggered by matches to the entry’s
Local
traffic selector.