418
CN4093 Application Guide for N/OS 8.4
IPsec Protocols
The
Enterprise
NOS
implementation
of
IPsec
supports
the
following
protocols:
Authentication
Header
(AH)
AHs
provide
connectionless
integrity
and
data
origin
authentication
for
IP
packets,
and
provide
protection
against
replay
attacks.
In
IPv6,
the
AH
protects
the
AH
itself,
the
Destination
Options
extension
header
after
the
AH,
and
the
IP
payload.
It
also
protects
the
fixed
IPv6
header
and
all
extension
headers
before
the
AH,
except
for
the
mutable
fields
DSCP,
ECN,
Flow
Label,
and
Hop
Limit.
AH
is
defined
in
RFC
4302.
Encapsulating
Security
Payload
(ESP)
ESPs
provide
confidentiality,
data
origin
authentication,
integrity,
an
anti
‐
replay
service
(a
form
of
partial
sequence
integrity),
and
some
traffic
flow
confidentiality.
ESPs
may
be
applied
alone
or
in
combination
with
an
AH.
ESP
is
defined
in
RFC
4303.
Internet
Key
Exchange
Version
2
(IKEv2)
IKEv2
is
used
for
mutual
authentication
between
two
network
elements.
An
IKE
establishes
a
security
association
(SA)
that
includes
shared
secret
information
to
efficiently
establish
SAs
for
ESPs
and
AHs,
and
a
set
of
cryptographic
algorithms
to
be
used
by
the
SAs
to
protect
the
associated
traffic.
IKEv2
is
defined
in
RFC
4306.
Using
IKEv2
as
the
foundation,
IPsec
supports
ESP
for
encryption
and/or
authentication,
and/or
AH
for
authentication
of
the
remote
partner.
Both
ESP
and
AH
rely
on
security
associations.
A
security
association
(SA)
is
the
bundle
of
algorithms
and
parameters
(such
as
keys)
that
encrypt
and
authenticate
a
particular
flow
in
one
direction.
Содержание Flex System Fabric CN4093
Страница 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Страница 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Страница 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Страница 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Страница 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Страница 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Страница 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Страница 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Страница 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Страница 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Страница 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Страница 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Страница 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Страница 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Страница 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Страница 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Страница 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Страница 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Страница 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Страница 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Страница 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Страница 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Страница 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Страница 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Страница 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Страница 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Страница 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Страница 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Страница 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Страница 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Страница 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Страница 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Страница 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Страница 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Страница 633: ......
Страница 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...