Brocade Network Advisor SAN User Manual
769
53-1002696-01
IPsec and IKE implementation over FCIP
22
IPsec for the 4 Gbps platforms
IPsec uses some terms that you should be familiar with before beginning your configuration. These
are standard terms, but are included here for your convenience.
The following limitations apply to using IPsec:
•
IPsec-specific statistics are not supported.
•
To change the configuration of a secure tunnel, you must delete the tunnel and recreate it.
•
There is no RAS message support for IPsec.
•
IPsec can only be configured on IPv4 based tunnels.
•
Secure Tunnels cannot be defined with VLAN Tagged connections.
•
For the 4 Gbps Extension switch and Blade:
-
IPv6, NAT, and AH are not supported when IPsec is implemented.
-
You can only create a single secure tunnel on a port; you cannot create a nonsecure tunnel
on the same port as a secure tunnel.
-
Jumbo frames are not supported.
Term
Definition
AES
Advanced Encryption Standard. FIPS 197 endorses the Rijndael encryption algorithm as the
approved AES for use by US Government organizations and others to protect sensitive
information. It replaces DES as the encryption standard.
AES-XCBC
Cipher Block Chaining. A key-dependent one-way hash function (MAC) used with AES in
conjunction with the Cipher-Block-Chaining mode of operation, suitable for securing messages
of varying lengths, such as IP datagrams.
AH
Authentication Header - like ESP, AH provides data integrity, data source authentication, and
protection against replay attacks but does not provide confidentiality.
DES
Data Encryption Standard is the older encryption algorithm that uses a 56-bit key to encrypt
blocks of 64-bit plain text. Because of the relatively shorter key length, it is not a secured
algorithm and no longer approved for Federal use.
3DES
Triple DES is a more secure variant of DES. It uses three different 56-bit keys to encrypt blocks
of 64-bit plain text. The algorithm is FIPS-approved for use by Federal agencies.
ESP
Encapsulating Security Payload is the IPsec protocol that provides confidentiality, data integrity
and data source authentication of IP packets, and protection against replay attacks.
IKE
Internet Key Exchange is defined in RFC 2407, RFC 2408 and RFC 2409. IKEv2 is defined in
RFC 4306. IKE uses a Diffie-Hellman key exchange to set up a shared session secret, from
which cryptographic keys are derived and communicating parties are authenticated. The IKE
protocol creates a security association (SA) for both parties.
MD5
Message Digest 5, like SHA-1, is a popular one-way hash function used for authentication and
data integrity.
SHA
Secure Hash Algorithm, like MD5, is a popular one-way hash function used for authentication
and data integrity.
MAC
Message Authentication Code is a key-dependent, one-way hash function used for generating
and verifying authentication data.
HMAC
A stronger MAC because it is a keyed hash inside a keyed hash.
SA
Security Association is the collection of security parameters and authenticated keys that are
negotiated between IPsec peers.
Содержание Network Advisor 12.0.0
Страница 36: ...xxxvi Brocade Network Advisor SAN User Manual 53 1002696 01...
Страница 82: ...34 Brocade Network Advisor SAN User Manual 53 1002696 01 License downgrade 2...
Страница 86: ...38 Brocade Network Advisor SAN User Manual 53 1002696 01 Uninstalling a patch 3...
Страница 122: ...74 Brocade Network Advisor SAN User Manual 53 1002696 01 VM Manager discovery 4...
Страница 184: ...136 Brocade Network Advisor SAN User Manual 53 1002696 01 Fabric tracking 5...
Страница 214: ...166 Brocade Network Advisor SAN User Manual 53 1002696 01 User profiles 6...
Страница 236: ...188 Brocade Network Advisor SAN User Manual 53 1002696 01 Searching for an assigned event filter 7...
Страница 284: ...236 Brocade Network Advisor SAN User Manual 53 1002696 01 User defined performance monitors 8...
Страница 320: ...272 Brocade Network Advisor SAN User Manual 53 1002696 01 Grouping on the topology 9...
Страница 336: ...288 Brocade Network Advisor SAN User Manual 53 1002696 01 Microsoft System Center Operations Manager SCOM plug in 10...
Страница 434: ...386 Brocade Network Advisor SAN User Manual 53 1002696 01 Port Auto Disable 12...
Страница 442: ...394 Brocade Network Advisor SAN User Manual 53 1002696 01 Exporting Host port mapping 13...
Страница 450: ...402 Brocade Network Advisor SAN User Manual 53 1002696 01 Exporting storage port mapping 14...
Страница 536: ...488 Brocade Network Advisor SAN User Manual 53 1002696 01 Virtual FCoE port configuration 16...
Страница 552: ...504 Brocade Network Advisor SAN User Manual 53 1002696 01 Security configuration deployment 17...
Страница 878: ...830 Brocade Network Advisor SAN User Manual 53 1002696 01 Removing thresholds 24...
Страница 922: ...874 Brocade Network Advisor SAN User Manual 53 1002696 01 VLAN routing 26...
Страница 990: ...942 Brocade Network Advisor SAN User Manual 53 1002696 01 SAN Connection utilization 29...
Страница 998: ...950 Brocade Network Advisor SAN User Manual 53 1002696 01 Removing a frame monitor from a switch 30...
Страница 1138: ...1090 Brocade Network Advisor SAN User Manual 53 1002696 01 Call Home Event Tables B...
Страница 1144: ...1096 Brocade Network Advisor SAN User Manual 53 1002696 01 IP Performance monitoring events C...
Страница 1186: ...1138 Brocade Network Advisor SAN User Manual 53 1002696 01 Regular Expressions F...
Страница 1486: ...1438 Brocade Network Advisor SAN User Manual 53 1002696 01 Views H...