
Configuring IP Security Services
1-4
304111-A Rev 00
Security Protocols Overview
IPsec uses two protocols to provide traffic security:
• Encapsulating Security Payload (ESP)
• Authentication Header (AH)
You can use either protocol or both to protect data packets on a VPN.
Encapsulating Security Payload
The ESP protocol provides confidentiality (encryption) services. It can also
provide data integrity, data origin authentication, and an anti-replay service. One
or more of these security services must be applied whenever ESP is invoked.
ESP uses the Data Encryption Standard (DES) algorithm for encryption and
Hashing Message Authentication Code Message Digest 5 (HMAC MD5)
transform identifiers. For more information about DES, see “Security Protocols”
on page 2-9.
Authentication Header
The AH protocol provides data integrity, data origin authentication, and optional
anti-replay services.
The AH protocol uses HMAC MD5 transform identifiers.
Comentarios a estos manuales