Trusted Solaris Administrator's Procedures

MAC Checks on Messages Being Forwarded

On a Trusted Solaris gateway, accreditation checks are performed for the next hop and for the network interfaces.

If the packet has CIPSO label information, the following must be true for a packet to be forwarded:

If the packet has RIPSO label information, the following must be true for a packet to be forwarded:

If the label of a message is not within the minimum and maximum labels specified in the accreditation range for any of the destination host, gateways, or the network interface, the message is dropped.