Configuring IPsec to Protect H.248 Messages in Transport Mode
You can protect H.248 messages sent between the virtual BGF and the gateway controller using IPsec transport mode. Transport mode for H.248 messages is supported only on the Routing Engine. It is not supported on PICs.
To configure IPsec transport mode for H.248 messages:
- Configure a manual IPsec security association
at the [edit security ipsec] hierarchy level. Set the mode
to transport and set the direction to bidirectional.
See the security-association statement.
- Specify the security association to be used on
a virtual BGF. [edit services pgcp gateway bgf-1]user@host# set ipsec-transport-security-association bgf-sa
