724-746-5500 | blackbox.com
Page 92
Chapter 8: Virtual Private Networks
8.3 VPN Basics
This section discusses basic principles and operations in Virtual Private Networks.
A VPN device encapsulates information into IP packets, and can perform as a VPN gateway over public networks that use IP. As a
VPN gateway, a VPN device can perform IPsec tunnel initiation, IPsec tunnel termination, and IPsec passthrough. Those processes
use IPsec for VPN security, performing the functions listed in Table 8-1.
Table 8-1. IPsec Components Used in the WRT4000 Series Cellular Wireless Router.
Function
Protocols
Acronym
Standard
1
Key Exchange
Internet Key Exchange
IKE
version 1: RFC 2409
version 2: RFC 5996
Internet Security Association
and Key Management Protocol
ISAKMP
RFC2408
Encryption
Data Encryption Standard
DES
FIPS PUB 46-2
Triple Data Encryption Standard
3DES
SP 800-67, Revision 1 (per FIPS
PUB 140-2)
Advanced Encryption Standard
AES
FIPS PUB 197
Security Protocols
Encapsulating Security Payload
ESP
RFC 2406
Authentication Header
AH
RFC 2402
Authentication
Hashed Message Authentication
Code: Message Digest 5
HMAC MD5
RFC 1321;
For use of MD5 within ESP and
AH: RFC 2403
Hashed Message Authentication
Code: Secure Hash Algorithm 1
HMAC SHA-1
RFC 2404
Hashed Message Authentication
Code: Secure Hash Algorithm 3
HMAC SHA-3
FIPS PUB 180-4
1
Each Request for Comments (RFC) is from the Internet Engineering Task Force (IETF). Each Federal Information Processing
Standard Publication (FIPS PUB) and each Special Publication (SP) is from the National Institute of Standards and Technology
(NIST).
The WRT4000 Series Cellular Wireless Router can implement IKEv1 or IKEv2 VPN tunnels with any other IPsec compliant VPN
gateway or VPN client. The WRT4000 Series Cellular Wireless Router supports the following tunnel modes:
• Tunnel initiation: The device receives packets from a local user terminal. The device encapsulates the packets according to the
IPsec user policy, establishes a VPN tunnel across the public network to a remote VPN gateway, and sends the packets across
the VPN tunnel toward their destination.
• Tunnel passthrough: The device receives IPsec-encapsulated packets from a client VPN terminal, and provides transparent
forwarding of the IP packets according to the IPsec user policy. The device sends the packets across the public network without
repackaging them.
• Tunnel termination: The device terminates (accepts) an IPsec tunnel initiated by a remote VPN gateway or VPN client across the
public network. The device authenticates and unpackages the tunnel’s packets, and delivers them to the destination terminal.
(To perform tunnel termination, the device must maintain a table of VPN users that function as prospective tunnel initiators; see
The IP Policy Table.)
See the following:
• A Simple Virtual Private Network
• Tunnel Modes
• Tunnel Support
Содержание WRT4000-ANT
Страница 141: ...724 746 5500 blackbox com Page 141 NOTES...
Страница 142: ...724 746 5500 blackbox com Page 142 NOTES...
Страница 143: ...724 746 5500 blackbox com Page 143 NOTES...