
240 Chapter 13 VPN
NN47922-500
Main Mode ensures the highest level of security when the communicating parties
are negotiating authentication (phase 1). It uses 6 messages in three round trips:
SA negotiation, Diffie-Hellman exchange, and an exchange of nonces (a nonce is
a random number). This mode features identity protection (your identity is not
revealed in the negotiation).
Aggressive Mode is quicker than Main Mode because it eliminates several steps
when the communicating parties are negotiating authentication (phase 1).
However the trade-off is that faster speed limits its negotiating power and it also
does not provide identity protection. It is useful in remote access situations where
the address of the initiator is not known by the responder and both parties want to
use preshared key authentication.
Preshared key
A preshared key identifies a communicating party during a phase 1 IKE
negotiation. It is called preshared because you have to share it with another party
before you can communicate with the party over a secure connection.
Diffie-Hellman (DH) Key Groups
Diffie-Hellman (DH) is a public-key cryptography protocol that allows two
parties to establish a shared secret over an unsecured communications channel.
Diffie-Hellman is used within IKE SA setup to establish session keys. 768-bit
(Group 1 - DH1), 1 024-bit (Group 2 – DH2) and 1 536-bit (Group 5 - DH5)
Diffie-Hellman groups are supported. Upon completion of the Diffie-Hellman
exchange, the two peers have a shared secret, but the IKE SA is not authenticated.
For authentication, use preshared keys.
Perfect Forward Secrecy (PFS)
Enabling PFS means that the key is transient. The key is thrown away and
replaced by a brand new key using a new Diffie-Hellman exchange for each new
IPSec SA setup. With PFS enabled, if one key is compromised, previous and
subsequent keys are not compromised, because subsequent keys are not derived
from previous keys. The (time consuming) Diffie-Hellman exchange is the
trade-off for this extra security.
Comentarios a estos manuales