P-793H v 2 Support Notes
There are two protocols provided by IPSec, they are AH (Authentication
Header, protocol number 51) and ESP (Encapsulated Security Payload,
protocol number 50).
8. What are the differences between 'Transport mode' and 'Tunnel mode?
The IPSec protocols (AH and ESP) can be used to protect either an entire IP
payload or only the upper-layer protocols of an IP payload. Transport mode is
mainly for an IP host to protect the data generated locally, while tunnel mode is
for security gateway to provide IPSec service for other machines lacking of
IPSec capability.
In this case, Transport mode only protects the upper-layer protocols of IP
payload (user data). Tunneling mode protects the entire IP payload including
user data.
There is no restriction that the IPSec hosts and the security gateway must be
separate machines. Both IPSec protocols, AH and ESP, can operate in either
transport mode and tunnel mode.
9. What is SA?
A Security Association (SA) is a contract between two parties indicating what
security parameters, such as keys and algorithms they will use.
10. What is IKE?
IKE is short for Internet Key Exchange. Key Management allows you to
determine whether to use IKE (ISAKMP) or manual key configuration to set up a
VPN.
There are two phases in every IKE negotiation- phase 1 (Authentication) and
phase 2 (Key Exchange). Phase 1 establishes an IKE SA and phase 2 uses
that SA to negotiate SAs for IPSec.
11. What is Pre-Shared Key?
A pre-shared key identifies a communicating party during a phase 1 IKE
negotiation. It is called 'Pre-shared' because you have to share it with another
party before you can communicate with them over a secure connection.
12. What are the differences between IKE and manual key VPN?
The only difference between IKE and manual key is how the encryption keys
and SPIs are determined.
30
All contents copy right © 2010 Zy XEL Communications Corporation.