IP Packets forwarded over the SWVC can be encrypted. The ENCRYPTION Policy Criterion provides a mechanism to specify whether or not encryption is required. It can have the value Yes or Either.

[R23] If Policy Criterion ENCRYPTION=Yes is applied to an Application Flow, then the Application Flow MUST be encrypted before it is forwarded over the Underlay Connectivity Service.

[R23] means that encryption is applied by the SD-WAN Edge before packets are forwarded over the UCS UNI, and decryption is applied to packets received at the destination SD-WAN Edge. This is typically implemented by instantiating an encrypted TVC.10

[R24] If the Policy Criterion ENCRYPTION=Either is applied to an Application Flow, then this Policy Criterion MUST NOT be considered in the forwarding decision for the Application Flow.

IP Packets forwarded over the SWVC can be encrypted. The ENCRYPTION Policy Criterion provides a mechanism to specify whether or not encryption is required. It can have the value Yes or Either.

[R23] If Policy Criterion ENCRYPTION=Yes is applied to an Application Flow, then the Application Flow MUST be encrypted before it is forwarded over the Underlay Connectivity Service.

[R23] means that encryption is applied by the SD-WAN Edge before packets are forwarded over the UCS UNI, and decryption is applied to packets received at the destination SD-WAN Edge. This is typically implemented by instantiating an encrypted TVC.10

[R24] If the Policy Criterion ENCRYPTION=Either is applied to an Application Flow, then this Policy Criterion MUST NOT be considered in the forwarding decision for the Application Flow.

  • No labels