340
NE2552E Application Guide for ENOS 8.4
IPsec Protocols
The
Lenovo
ENOS
implementation
of
IPsec
supports
the
following
protocols:
Authentication
Header
(AH)
AHs
provide
connectionless
integrity
and
data
origin
authentication
for
IP
packets,
and
provide
protection
against
replay
attacks.
In
IPv6,
the
AH
protects
the
AH
itself,
the
Destination
Options
extension
header
after
the
AH,
and
the
IP
payload.
It
also
protects
the
fixed
IPv6
header
and
all
extension
headers
before
the
AH,
except
for
the
mutable
fields
DSCP,
ECN,
Flow
Label,
and
Hop
Limit.
AH
is
defined
in
RFC
4302.
Encapsulating
Security
Payload
(ESP)
ESPs
provide
confidentiality,
data
origin
authentication,
integrity,
an
anti
‐
replay
service
(a
form
of
partial
sequence
integrity),
and
some
traffic
flow
confidentiality.
ESPs
may
be
applied
alone
or
in
combination
with
an
AH.
ESP
is
defined
in
RFC
4303.
Internet
Key
Exchange
Version
2
(IKEv2)
IKEv2
is
used
for
mutual
authentication
between
two
network
elements.
An
IKE
establishes
a
security
association
(SA)
that
includes
shared
secret
information
to
efficiently
establish
SAs
for
ESPs
and
AHs,
and
a
set
of
cryptographic
algorithms
to
be
used
by
the
SAs
to
protect
the
associated
traffic.
IKEv2
is
defined
in
RFC
4306.
Using
IKEv2
as
the
foundation,
IPsec
supports
ESP
for
encryption
and/or
authentication,
and/or
AH
for
authentication
of
the
remote
partner.
Both
ESP
and
AH
rely
on
security
associations.
A
security
association
(SA)
is
the
bundle
of
algorithms
and
parameters
(such
as
keys)
that
encrypt
and
authenticate
a
particular
flow
in
one
direction.
Summary of Contents for ThinkSystem NE2552E
Page 27: ... Copyright Lenovo 2018 27 Part 1 Getting Started ...
Page 28: ...28 NE2552E Application Guide for ENOS 8 4 ...
Page 70: ...70 NE2552E Application Guide for ENOS 8 4 ...
Page 85: ... Copyright Lenovo 2018 85 Part 2 Securing the Switch ...
Page 86: ...86 NE2552E Application Guide for ENOS 8 4 ...
Page 112: ...112 NE2552E Application Guide for ENOS 8 4 ...
Page 134: ...134 NE2552E Application Guide for ENOS 8 4 ...
Page 154: ...154 NE2552E Application Guide for ENOS 8 4 ...
Page 194: ...194 NE2552E Application Guide for ENOS 8 4 ...
Page 218: ...218 NE2552E Application Guide for ENOS 8 4 ...
Page 234: ...234 NE2552E Application Guide for ENOS 8 4 ...
Page 238: ...238 NE2552E Application Guide for ENOS 8 4 ...
Page 239: ... Copyright Lenovo 2018 239 Part 4 Advanced Switching Features ...
Page 240: ...240 NE2552E Application Guide for ENOS 8 4 ...
Page 242: ...242 NE2552E Application Guide for ENOS 8 4 ...
Page 278: ...278 NE2552E Application Guide for ENOS 8 4 ...
Page 284: ...284 NE2552E Application Guide for ENOS 8 4 ...
Page 314: ...314 NE2552E Application Guide for ENOS 8 4 ...
Page 338: ...338 NE2552E Application Guide for ENOS 8 4 ...
Page 374: ...374 NE2552E Application Guide for ENOS 8 4 ...
Page 388: ...388 NE2552E Application Guide for ENOS 8 4 ...
Page 418: ...418 NE2552E Application Guide for ENOS 8 4 ...
Page 430: ...430 NE2552E Application Guide for ENOS 8 4 ...
Page 432: ...432 NE2552E Application Guide for ENOS 8 4 ...
Page 436: ...436 NE2552E Application Guide for ENOS 8 4 ...
Page 460: ...460 NE2552E Application Guide for ENOS 8 4 ...
Page 461: ... Copyright Lenovo 2018 461 Part 7 Network Management ...
Page 462: ...462 NE2552E Application Guide for ENOS 8 4 ...
Page 476: ...476 NE2552E Application Guide for ENOS 8 4 ...
Page 498: ...498 NE2552E Application Guide for ENOS 8 4 ...
Page 520: ...520 NE2552E Application Guide for ENOS 8 4 ...
Page 534: ...534 NE2552E Application Guide for ENOS 8 4 ...
Page 536: ...536 NE2552E Application Guide for ENOS 8 4 ...
Page 544: ...544 NE2552E Application Guide for ENOS 8 4 ...
Page 549: ... Copyright Lenovo 2018 549 Part 9 Appendices ...
Page 550: ...550 NE2552E Application Guide for ENOS 8 4 ...
Page 566: ...566 NE2552E Application Guide for ENOS 8 4 ...
Page 572: ...572 NE2552E Application Guide for ENOS 8 4 ...
Page 573: ......
Page 574: ...Part Number 01KN246 Printed in USA IP P N 01KN246 ...