23
Internet Protocol Security (IPSec)
IPSec is an end-to-end security scheme for protecting IP communications by authenticating and
encrypting all packets in a communication session. Use IPSec between hosts, between gateways, or
between hosts and gateways.
IPSec is compatible with Telnet and file transfer protocols (FTPs). It supports two operational modes:
Transport and Tunnel.
• Transport mode — (default) Use to encrypt only the payload of the packet. Routing information is
unchanged.
• Tunnel mode — Use to encrypt the entire packet including the routing information of the IP header.
Typically used when creating virtual private networks (VPNs).
NOTE: Due to performance limitations on the control processor, you cannot enable IPSec on all
packets in a communication session.
IPSec uses the following protocols:
•
Authentication Headers (AH)
— Disconnected integrity and origin authentication for IP packets
•
Encapsulating Security Payload (ESP)
— Confidentiality, authentication, and data integrity for IP
packets
•
Security Associations (SA)
— Necessary algorithmic parameters for AH and ESP functionality
IPSec supports the following authentication and encryption algorithms:
• Authentication only:
– MD5
– SHA1
• Encryption only:
– 3DES
– CBC
– DES
• ESP Authentication and Encryption:
– MD5 & 3DES
– MD5 & CBC
– MD5 & DES
– SHA1 & 3DES
– SHA1 & CBC
– SHA1 & DES
Internet Protocol Security (IPSec)
477
Summary of Contents for S4820T
Page 1: ...Dell Configuration Guide for the S4820T System 9 8 0 0 ...
Page 282: ...Dell 282 Control Plane Policing CoPP ...
Page 622: ...Figure 81 Configuring Interfaces for MSDP 622 Multicast Source Discovery Protocol MSDP ...
Page 623: ...Figure 82 Configuring OSPF and BGP for MSDP Multicast Source Discovery Protocol MSDP 623 ...
Page 629: ...Figure 86 MSDP Default Peer Scenario 2 Multicast Source Discovery Protocol MSDP 629 ...
Page 630: ...Figure 87 MSDP Default Peer Scenario 3 630 Multicast Source Discovery Protocol MSDP ...
Page 751: ...10 11 5 2 00 00 05 00 02 04 Member Ports Te 1 2 1 PIM Source Specific Mode PIM SSM 751 ...
Page 905: ...Figure 112 Single and Double Tag First byte TPID Match Service Provider Bridging 905 ...
Page 979: ...6 Member not present 7 Member not present Stacking 979 ...
Page 981: ...storm control Storm Control 981 ...
Page 1103: ...Figure 134 Setup OSPF and Static Routes Virtual Routing and Forwarding VRF 1103 ...