420
CN4093 Application Guide for N/OS 8.4
Setting up Authentication
Before
you
can
use
IPsec,
you
need
to
have
key
policy
authentication
in
place.
There
are
two
types
of
key
policy
authentication:
Preshared
key
(default)
The
parties
agree
on
a
shared,
secret
key
that
is
used
for
authentication
in
an
IPsec
policy.
During
security
negotiation,
information
is
encrypted
before
transmission
by
using
a
session
key
created
by
using
a
Diffie
‐
Hellman
calculation
and
the
shared,
secret
key.
Information
is
decrypted
on
the
receiving
end
using
the
same
key.
One
IPsec
peer
authenticates
the
other
peer
ʹ
s
packet
by
decryption
and
verification
of
the
hash
inside
the
packet
(the
hash
inside
the
packet
is
a
hash
of
the
preshared
key).
If
authentication
fails,
the
packet
is
discarded.
Digital
certificate
(using
RSA
algorithms)
The
peer
being
validated
must
hold
a
digital
certificate
signed
by
a
trusted
Certificate
Authority
and
the
private
key
for
that
digital
certificate.
The
side
performing
the
authentication
only
needs
a
copy
of
the
trusted
certificate
authorities
digital
certificate.
During
IKEv2
authentication,
the
side
being
validated
sends
a
copy
of
the
digital
certificate
and
a
hash
value
signed
using
the
private
key.
The
certificate
can
be
either
generated
or
imported.
Note:
During
the
IKEv2
negotiation
phase,
the
digital
certificate
takes
precedence
over
the
preshared
key.
Creating an IKEv2 Proposal
With
IKEv2,
a
single
policy
can
have
multiple
encryption
and
authentication
types,
as
well
as
multiple
integrity
algorithms.
To
create
an
IKEv2
proposal:
1.
Enter
IKEv2
proposal
mode.
2.
Set
the
DES
encryption
algorithm.
3.
Set
the
authentication
integrity
algorithm
type.
4.
Set
the
Diffie
‐
Hellman
group.
CN 4093(config)#
ikev2 proposal
CN 4093(config-ikev2-prop)#
encryption {3des|aes-cbc|des}
(default:
3des
)
CN 4093(config-ikev2-prop)#
integrity {md5|sha1}
(default:
sha1
)
CN 4093(config-ikev2-prop)#
group {1|2|5|14|24}
(default:
2
)
Содержание Flex System Fabric CN4093
Страница 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Страница 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Страница 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Страница 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Страница 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Страница 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Страница 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Страница 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Страница 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Страница 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Страница 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Страница 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Страница 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Страница 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Страница 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Страница 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Страница 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Страница 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Страница 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Страница 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Страница 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Страница 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Страница 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Страница 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Страница 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Страница 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Страница 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Страница 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Страница 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Страница 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Страница 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Страница 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Страница 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Страница 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Страница 633: ......
Страница 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...