HP-UX IPSec version A.02.01 Administrator's Guide
Interoperability
Microsoft
Appendix B 243
Microsoft
HP-UX IPSec can interoperate with Microsoft IPsec implementations.
Products and Versions
HP-UX IPSec A.02.01 has been successfully tested with the following
Microsoft products and versions:
• Windows XP Professional version 2002, Service Pack 1
• Windows 2003 Server Enterprise Edition, Service Pack 2
• Windows 2000, Service Pack 4
Functionality
The following functionality was tested:
• IKE using preshared key authentication
• IKE using RSA signature authentication
• Cleartext over an IPsec tunnel (HP-UX IPSec end system to Cisco
gateway)
• IPsec transport over an IPsec tunnel (HP-UX IPSec end system to
Cisco gateway)
Tips
The following tips may help you configure HP-UX IPSec and Microsoft
IPsec implementations:
• To configure host-to-host IPsec security, configure one rule and set
the Mirror field to yes. Specify the HP-UX system address as the
destination address.
• To configure the end-to-end tunnel, you must configure two rules on
the Microsoft system. In Microsoft IPsec implementations, tunnel
IPsec rules must be uni-directional and specify only one tunnel
endpoint. (HP-UX IPSec tunnel IPsec policies are bi-directional and
apply to packets in both directions.) For each tunnel IPsec policy
configured on HP-UX, you must configure two corresponding tunnel