IP SEC - PacketLife.net
Jeremy AlgorithmsDESSymmetric56TypeKey Length (Bits)AESSymmetric3DESSymmetric168WeakSt rengthMediumRSAAsymmetric128/192/2561024 +StrongStrongHashing AlgorithmsMD5128Length (Bits)SHA-1160MediumStrengthStrongIntern et Security Association and Key Management Protocol (ISAKMP)A framework for the negotiation and management of security associations between peers (traverses UDP/500)Internet Key Exchange (IKE)Responsible for key agreement using asymmetric cryptographyEncapsulating Security Payload (ESP)Provides data encryption, data integrity, and peer authentication; IP protocol 50Authentication Header (AH)Provides data integrity and peer authentication, but not data encryption; IP protocol 51IPsec ModesIKE PhasesPhase 1A bidirectional ISAKMP SA is established between peers to provide a secure management channel (IKE in main or aggressive mode)Phase (optional)Xauth can optionally be implemented to enforce user authenticationPhase 2Two unidirectional IPsec SAs are established for data transfer using separate keys (IKE quick mode)Transport ModeThe ESP or AH header is inserted behind the IP header; the IP header can be authenticated but not encryptedTunnel ModeA new IP header is created in place of the original; this allows for encryption of the entire original packetConfigurationcrypto isakmp policy 10encryption aes 256hash shaauthentication pre-sharegroup 2lifetime 3600ISAKMP Policycrypto isakmp key 1 MySecretKeyaddress Pre-Shared Keycrypto ipsec transform-set MyTSesp-aes 256
Medium RSA Asymmetric 128/192/256 1024+ Strong Strong Hashing Algorithms MD5 128 Length (Bits) SHA-1 160 Medium Strength Strong ... Hash Message Authentication Code (HMAC) A hash of the data and secret key used to provide message authenticity Diffie-Hellman Exchange A shared secret key is established over an
Download IP SEC - PacketLife.net
Information
Domain:
Source:
Link to this page:
Please notify us if you found a problem with this document: