Technical Documentation

Configuring IPsec to Protect H.248 Messages in Transport Mode

You can protect H.248 messages sent between the virtual BGF and the gateway controller using IPsec transport mode. Transport mode for H.248 messages is supported only on the Routing Engine. It is not supported on PICs.

To configure IPsec transport mode for H.248 messages:

  1. Configure a manual IPsec security association at the [edit security ipsec] hierarchy level. Set the mode to transport and set the direction to bidirectional.

    See the security-association statement.

  2. Specify the security association to be used on a virtual BGF.
    [edit services pgcp gateway bgf-1]user@host# set ipsec-transport-security-association bgf-sa

Published: 2010-08-03

Help
|
My Account
|
Log Out