TMS zl Management and Configuration Guide ST.1.1.100430

B-27
Glossary
S
SA Security Association. Secure communication between two network devices
that is created from shared security information. A SA is used in IKE. For more
information, see RFC 4306 at http://www.ietf.org/rfc/rfc4603.txt.
SA lifetime The time in seconds that can pass or amount of data in kilobytes that can be
sent before the SA must be renegotiated.
schedule object A named object that specifies the days and times of day that a specific firewall
access policy applies.
scheduled policy A firewall access policy to which a schedule object has been applied.
SCEP Simple Certificate Enrollment Protocol. A PKI communication protocol to
provide secure issuance of certificates in a scalable manner. For more infor-
mation, see the Internet Draft at http://www.ietf.org/internet-drafts/draft-
nourse-scep-15.txt.
SCP Secure Copy Protocol. Encrypts data packets over an SSH connection.
security
association
See SA.
Self The zone that contains all of the modules interface and NAT addresses. All
traffic that terminates at the module is destined for Self, and all traffic that
originates with the module is from Self.
sequence number
out of range
When packets are received outside of the TCP sliding window's parameters.
This can be an indication of an attack.
sequence number
overflow
A condition wherein an IPsec SA exhausts all of its sequence numbers before
the session has ended.
sequence number
prediction
An attack in which the attacker guesses or sniffs a TCP session sequence
number to gain unwarranted access to a network. See ISN.
serial console A management access method that requires a serial connection between the
host switch and a workstation plus terminal-emulation software.
serial number A unique number that identifies each TMS zl Module. The serial number is
displayed on the dashboard.