P-202H Plus v2 Support Notes
for security gateway to provide IPSec service for other machines lacking of IPSec
capability.
In this case, Transport mode only protects the upper-layer protocols of IP
payload (user data). Tunneling mode protects the entire IP payload including
user data.
There is no restriction that the IPSec hosts and the security gateway must be
separate machines. Both IPSec protocols, AH and ESP, can operate in either
transport mode and tunnel mode.
9. What is SA?
A Security Association (SA) is a contract between two parties indicating what
security parameters, such as keys and algorithms they will use.
10. What is IKE?
IKE is short for Internet Key Exchange. Key Management allows you to
determine whether to use IKE (ISAKMP) or manual key configuration to set up a
VPN.
There are two phases in every IKE negotiation- phase 1 (Authentication) and
phase 2 (Key Exchange). Phase 1 establishes an IKE SA and phase 2 uses that
SA to negotiate SAs for IPSec.
11. What is Pre-Shared Key?
A pre-shared key identifies a communicating party during a phase 1 IKE
negotiation. It is called 'Pre-shared' because you have to share it with another
party before you can communicate with them over a secure connection.
12. What are the differences between IKE and manual key VPN?
The only difference between IKE and manual key is how the encryption keys and
SPIs are determined.
•
For IKE VPN, the key and SPIs are negotiated from one VPN gateway to
the other. Afterward, two VPN gateways use this negotiated keys and
SPIs to send packets between two networks.
•
For manual key VPN, the encryption key, authentication key (if needed),
and SPIs are predetermined by the administrator when configuring the
security association.
All contents copyright © 2006 ZyXEL Communications Corporation.
29
Summary of Contents for P-202H Plus v2
Page 201: ...P 202H Plus v2 Support Notes All contents copyright 2006 ZyXEL Communications Corporation 201...
Page 215: ...P 202H Plus v2 Support Notes All contents copyright 2006 ZyXEL Communications Corporation 215...
Page 259: ...P 202H Plus v2 Support Notes All contents copyright 2006 ZyXEL Communications Corporation 259...
Page 267: ...P 202H Plus v2 Support Notes All contents copyright 2006 ZyXEL Communications Corporation 267...
Page 284: ...P 202H Plus v2 Support Notes All contents copyright 2006 ZyXEL Communications Corporation 284...
Page 301: ...P 202H Plus v2 Support Notes All contents copyright 2006 ZyXEL Communications Corporation 301...
Page 318: ...P 202H Plus v2 Support Notes All contents copyright 2006 ZyXEL Communications Corporation 318...
Page 323: ...P 202H Plus v2 Support Notes All contents copyright 2006 ZyXEL Communications Corporation 323...
Page 356: ...P 202H Plus v2 Support Notes All contents copyright 2006 ZyXEL Communications Corporation 356...
Page 358: ...P 202H Plus v2 Support Notes All contents copyright 2006 ZyXEL Communications Corporation 358...
Page 360: ...P 202H Plus v2 Support Notes All contents copyright 2006 ZyXEL Communications Corporation 360...
Page 361: ...P 202H Plus v2 Support Notes All contents copyright 2006 ZyXEL Communications Corporation 361...