Internet Protocol Security (IPSec)
Internet protocol security (IPSec) is an end-to-end security scheme for protecting IP communications by authenticating and encrypting all
packets in a communication session. Use IPSec between hosts, between gateways, or between hosts and gateways.
IPSec is compatible with Telnet and FTP protocols. It supports two operational modes: Transport and Tunnel.
•
Transport mode — (default) Use to encrypt only the payload of the packet. Routing information is unchanged.
•
Tunnel mode — Use to encrypt the entire packet including the routing information of the IP header. Typically used when creating virtual
private networks (VPNs).
NOTE:
Due to performance limitations on the control processor, you cannot enable IPSec on all packets in a communication
session.
IPSec uses the following protocols:
•
Authentication Headers (AH)
— Disconnected integrity and origin authentication for IP packets
•
Encapsulating Security Payload (ESP)
— Confidentiality, authentication, and data integrity for IP packets
•
Security Associations (SA)
— Necessary algorithmic parameters for AH and ESP functionality
IPSec supports the following authentication and encryption algorithms:
•
Authentication only:
•
MD5
•
SHA1
•
Encryption only:
•
3DES
•
CBC
•
DES
•
ESP Authentication and Encryption:
•
MD5 & 3DES
•
MD5 & CBC
•
MD5 & DES
•
SHA1 & 3DES
•
SHA1 & CBC
•
SHA1 & DES
Configuring IPSec
The following sample configuration shows how to configure FTP and telnet for IPSec.
1
Define the transform set.
CONFIGURATION mode
crypto ipsec transform-set myXform-seta esp-authentication md5 esp-encryption des
2
Define the crypto policy.
CONFIGURATION mode
23
432
Internet Protocol Security (IPSec)
Содержание S4048T-ON
Страница 1: ...Dell Configuration Guide for the S4048 ON System 9 11 2 1 ...
Страница 148: ...Figure 10 BFD Three Way Handshake State Changes 148 Bidirectional Forwarding Detection BFD ...
Страница 251: ...Dell Control Plane Policing CoPP 251 ...
Страница 363: ... RPM Synchronization GARP VLAN Registration Protocol GVRP 363 ...
Страница 511: ...Figure 64 Inspecting the LAG Configuration Link Aggregation Control Protocol LACP 511 ...
Страница 512: ...Figure 65 Inspecting Configuration of LAG 10 on ALPHA 512 Link Aggregation Control Protocol LACP ...
Страница 515: ...Figure 67 Inspecting a LAG Port on BRAVO Using the show interface Command Link Aggregation Control Protocol LACP 515 ...
Страница 516: ...Figure 68 Inspecting LAG 10 Using the show interfaces port channel Command 516 Link Aggregation Control Protocol LACP ...
Страница 558: ...Figure 84 Configuring Interfaces for MSDP 558 Multicast Source Discovery Protocol MSDP ...
Страница 559: ...Figure 85 Configuring OSPF and BGP for MSDP Multicast Source Discovery Protocol MSDP 559 ...
Страница 560: ...Figure 86 Configuring PIM in Multiple Routing Domains 560 Multicast Source Discovery Protocol MSDP ...
Страница 564: ...Figure 88 MSDP Default Peer Scenario 2 564 Multicast Source Discovery Protocol MSDP ...
Страница 565: ...Figure 89 MSDP Default Peer Scenario 3 Multicast Source Discovery Protocol MSDP 565 ...
Страница 729: ...protocol spanning tree pvst no disable vlan 300 bridge priority 4096 Per VLAN Spanning Tree Plus PVST 729 ...
Страница 841: ...Figure 115 Single and Double Tag TPID Match Service Provider Bridging 841 ...
Страница 842: ...Figure 116 Single and Double Tag First byte TPID Match 842 Service Provider Bridging ...