Security Policy Database

E123428

The Security Policy Database is a core IPsec component that defines the rules and conditions under which network traffic must be protected, bypassed, or discarded.

All labels observed (1)

Label Occurrences
Security Policy Database canonical 3

How this entity was disambiguated

Statements (47)

Predicate Object
instanceOf IPsec component ⓘ
network security database ⓘ
actionType BYPASS ⓘ
DISCARD ⓘ
PROTECT ⓘ
alsoKnownAs SPD ⓘ
belongsToProtocolSuite IPsec ⓘ
canBeConfiguredVia IPsec policy management utilities ⓘ
operating system security tools ⓘ
contains IPsec usage requirements ⓘ
policy entries ⓘ
processing actions ⓘ
security policies ⓘ
selectors ⓘ
controls application of IPsec protection to packets ⓘ
definedIn IPsec architecture ⓘ
determines whether a Security Association is required ⓘ
ensures consistent application of IPsec policies ⓘ
evaluatedBy inbound packet processing ⓘ
outbound packet processing ⓘ
goal control protection of network traffic based on defined rules ⓘ
managedBy system administrator ⓘ
mapsTo Security Associations in the Security Association Database ⓘ
operatesAtLayer network layer ⓘ
policyDecisionPointFor IPsec packet handling ⓘ
policyEntryIncludes action to apply to matching traffic ⓘ
destination IP address selectors ⓘ
destination port selectors ⓘ
direction of traffic ⓘ
source IP address selectors ⓘ
source port selectors ⓘ
upper-layer protocol selectors ⓘ
predecessorSpecification RFC 2401 ⓘ
primaryFunction define security policies for IP traffic ⓘ
determine whether traffic is protected, bypassed, or discarded ⓘ
relatedTo Security Association Database ⓘ
scope per-host IPsec policies ⓘ
per-interface IPsec policies ⓘ
per-traffic-selector policies ⓘ
specifiedIn RFC 4301 ⓘ
supports transport mode IPsec policies ⓘ
tunnel mode IPsec policies ⓘ
usedBy IPsec implementation ⓘ
IPsec key management subsystem ⓘ
IPsec processing engine ⓘ
usedFor access control decisions on IP packets ⓘ
traffic selection for IPsec processing ⓘ

How these facts were elicited

Referenced by (3)

Full triples — surface form annotated when it differs from this entity's canonical label.

IPsec → usesConcept → Security Policy Database ⓘ
RFC 2401 → definesConcept → Security Policy Database ⓘ
RFC 4301 → defines → Security Policy Database ⓘ