© Copyright Lenovo 2018
Chapter 23: Using IPsec with IPv6
341
Using IPsec with the NE2552E
IPsec
supports
the
fragmentation
and
reassembly
of
IP
packets
that
occurs
when
data
goes
to
and
comes
from
an
external
device.
The
Lenovo
ThinkSystem
NE2552E
Flex
Switch
acts
as
an
end
node
that
processes
any
fragmentation
and
reassembly
of
packets
but
does
not
forward
the
IPsec
traffic.
The
IKEv2
key
must
be
authenticated
before
you
can
use
IPsec.
The
security
protocol
for
the
session
key
is
either
ESP
or
AH.
Outgoing
packets
are
labeled
with
the
SA
SPI
(Security
Parameter
Index),
which
the
remote
device
will
use
in
its
verification
and
decryption
process.
Every
outgoing
IPv6
packet
is
checked
against
the
IPsec
policies
in
force.
For
each
outbound
packet,
after
the
packet
is
encrypted,
the
software
compares
the
packet
size
with
the
MTU
size
that
it
either
obtains
from
the
default
minimum
maximum
transmission
unit
(MTU)
size
(1500)
or
from
path
MTU
discovery.
If
the
packet
size
is
larger
than
the
MTU
size,
the
receiver
drops
the
packet
and
sends
a
message
containing
the
MTU
size
to
the
sender.
The
sender
then
fragments
the
packet
into
smaller
pieces
and
retransmits
them
using
the
correct
MTU
size.
The
maximum
traffic
load
for
each
IPSec
packet
is
limited
to
the
following:
IKEv2
SAs:
5
IPsec
SAs:
10
(5
SAs
in
each
direction)
SPDs:
20
(10
policies
in
each
direction)
IPsec
is
implemented
as
a
software
cryptography
engine
designed
for
handling
control
traffic,
such
as
network
management.
IPsec
is
not
designed
for
handling
data
traffic,
such
as
a
VPN.
Summary of Contents for ThinkSystem NE2552E
Page 27: ... Copyright Lenovo 2018 27 Part 1 Getting Started ...
Page 28: ...28 NE2552E Application Guide for ENOS 8 4 ...
Page 70: ...70 NE2552E Application Guide for ENOS 8 4 ...
Page 85: ... Copyright Lenovo 2018 85 Part 2 Securing the Switch ...
Page 86: ...86 NE2552E Application Guide for ENOS 8 4 ...
Page 112: ...112 NE2552E Application Guide for ENOS 8 4 ...
Page 134: ...134 NE2552E Application Guide for ENOS 8 4 ...
Page 154: ...154 NE2552E Application Guide for ENOS 8 4 ...
Page 194: ...194 NE2552E Application Guide for ENOS 8 4 ...
Page 218: ...218 NE2552E Application Guide for ENOS 8 4 ...
Page 234: ...234 NE2552E Application Guide for ENOS 8 4 ...
Page 238: ...238 NE2552E Application Guide for ENOS 8 4 ...
Page 239: ... Copyright Lenovo 2018 239 Part 4 Advanced Switching Features ...
Page 240: ...240 NE2552E Application Guide for ENOS 8 4 ...
Page 242: ...242 NE2552E Application Guide for ENOS 8 4 ...
Page 278: ...278 NE2552E Application Guide for ENOS 8 4 ...
Page 284: ...284 NE2552E Application Guide for ENOS 8 4 ...
Page 314: ...314 NE2552E Application Guide for ENOS 8 4 ...
Page 338: ...338 NE2552E Application Guide for ENOS 8 4 ...
Page 374: ...374 NE2552E Application Guide for ENOS 8 4 ...
Page 388: ...388 NE2552E Application Guide for ENOS 8 4 ...
Page 418: ...418 NE2552E Application Guide for ENOS 8 4 ...
Page 430: ...430 NE2552E Application Guide for ENOS 8 4 ...
Page 432: ...432 NE2552E Application Guide for ENOS 8 4 ...
Page 436: ...436 NE2552E Application Guide for ENOS 8 4 ...
Page 460: ...460 NE2552E Application Guide for ENOS 8 4 ...
Page 461: ... Copyright Lenovo 2018 461 Part 7 Network Management ...
Page 462: ...462 NE2552E Application Guide for ENOS 8 4 ...
Page 476: ...476 NE2552E Application Guide for ENOS 8 4 ...
Page 498: ...498 NE2552E Application Guide for ENOS 8 4 ...
Page 520: ...520 NE2552E Application Guide for ENOS 8 4 ...
Page 534: ...534 NE2552E Application Guide for ENOS 8 4 ...
Page 536: ...536 NE2552E Application Guide for ENOS 8 4 ...
Page 544: ...544 NE2552E Application Guide for ENOS 8 4 ...
Page 549: ... Copyright Lenovo 2018 549 Part 9 Appendices ...
Page 550: ...550 NE2552E Application Guide for ENOS 8 4 ...
Page 566: ...566 NE2552E Application Guide for ENOS 8 4 ...
Page 572: ...572 NE2552E Application Guide for ENOS 8 4 ...
Page 573: ......
Page 574: ...Part Number 01KN246 Printed in USA IP P N 01KN246 ...