Avaya Configuring IP Security Services Manual de usuario Pagina 31

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 100
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 30
Overview of IPsec
304111-B Rev 00
1-13
How IKE Negotiates Security Associations
The Internet Key Exchange (IKE) protocol automates the process of IPsec SA
configuration by creating an IKE SA for Protect SA and Unprotect SA
negotiation. Each IKE peer sends IPsec SA parameter negotiation information in a
secure IKE packet. The peers generate keys based on the agreed parameters and
then verify each others identity. Once this is done, the IPsec SA is established.
The IKE protocol itself is secured through an IKE SA created using the
Diffie-Hellman algorithm (Oakley) to determine the key, and the authentication
methods described in
Automated Security Associations Using Internet Key
Exchange (IKE)” on page 1-11. The Bay Networks implementation uses a
pre-shared key.
Security Parameter Index (SPI)
A security parameter index (SPI) is an arbitrary but unique 32-bit (4 byte) value
that, when combined with the IP destination address and the numeric value of the
security protocol used (ESP), uniquely identifies the SA for a data packet.
IPsec discards any incoming ESP packet if the SPI does not match any SA in the
inbound security associations database (SAD).
Vista de pagina 30
1 2 ... 26 27 28 29 30 31 32 33 34 35 36 ... 99 100

Comentarios a estos manuales

Sin comentarios