Table 11: Supported Transforms
(continued)
Description
Transform
IPSec performs AH protocol encapsulation using the SHA-1 hash function
with HMAC message authentication. SHA-1 is considered stronger than MD5.
AH-SHA
IPSec performs ESP protocol encapsulation using the MD5 hash function with
HMAC message authentication.
ESP-MD5
IPSec performs ESP protocol encapsulation using the SHA-1 hash function
with HMAC message authentication. SHA-1 is considered stronger than MD5.
ESP-SHA
IPSec performs ESP protocol encapsulation using the DES encryption
algorithm. DES uses a 56-bit symmetric key and is considered a weak
(breakable) encryption algorithm.
ESP-DES
IPSec performs ESP protocol encapsulation using the 3DES encryption
algorithm. 3DES uses a 168-bit symmetric encryption key and is widely
accepted as a strong encryption algorithm. Export control issues apply to
products that ship from the USA with 3DES.
ESP-3DES
Combination of ESP-MD5 and ESP-DES transforms.
ESP-DES-MD5
Combination of ESP-SHA and ESP-DES transforms.
ESP-DES-SHA
Combination of ESP-MD5 and ESP-3DES transforms.
ESP-3DES-MD5
Combination of ESP-SHA and ESP-3DES transforms.
ESP-3DES-SHA
Table 12 on page 137 lists the security functions achieved with the supported
transforms, and provides a view of which combinations can be used, depending on
security requirements.
Table 12: Supported Security Transform Combinations
Supported Transform Combinations
Security Type
AH-HMAC-MD5
AH-HMAC-SHA
ESP-HMAC-MD5
ESP-HMAC-SHA
Data authentication only
ESP-DES
ESP-3DES
Data confidentiality only
IPSec Concepts
■
137
Chapter 5: Configuring IPSec
Содержание JUNOSE 11.0.X IP SERVICES
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 0 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 0 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 0 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 0 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 0 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 0 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 0 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 0 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 0 x IP Services Configuration Guide...