© Copyright Lenovo 2018
Chapter 23: Using IPsec with IPv6
341
Using IPsec with the NE2552E
IPsec
supports
the
fragmentation
and
reassembly
of
IP
packets
that
occurs
when
data
goes
to
and
comes
from
an
external
device.
The
Lenovo
ThinkSystem
NE2552E
Flex
Switch
acts
as
an
end
node
that
processes
any
fragmentation
and
reassembly
of
packets
but
does
not
forward
the
IPsec
traffic.
The
IKEv2
key
must
be
authenticated
before
you
can
use
IPsec.
The
security
protocol
for
the
session
key
is
either
ESP
or
AH.
Outgoing
packets
are
labeled
with
the
SA
SPI
(Security
Parameter
Index),
which
the
remote
device
will
use
in
its
verification
and
decryption
process.
Every
outgoing
IPv6
packet
is
checked
against
the
IPsec
policies
in
force.
For
each
outbound
packet,
after
the
packet
is
encrypted,
the
software
compares
the
packet
size
with
the
MTU
size
that
it
either
obtains
from
the
default
minimum
maximum
transmission
unit
(MTU)
size
(1500)
or
from
path
MTU
discovery.
If
the
packet
size
is
larger
than
the
MTU
size,
the
receiver
drops
the
packet
and
sends
a
message
containing
the
MTU
size
to
the
sender.
The
sender
then
fragments
the
packet
into
smaller
pieces
and
retransmits
them
using
the
correct
MTU
size.
The
maximum
traffic
load
for
each
IPSec
packet
is
limited
to
the
following:
IKEv2
SAs:
5
IPsec
SAs:
10
(5
SAs
in
each
direction)
SPDs:
20
(10
policies
in
each
direction)
IPsec
is
implemented
as
a
software
cryptography
engine
designed
for
handling
control
traffic,
such
as
network
management.
IPsec
is
not
designed
for
handling
data
traffic,
such
as
a
VPN.
Содержание ThinkSystem NE2552E
Страница 27: ... Copyright Lenovo 2018 27 Part 1 Getting Started ...
Страница 28: ...28 NE2552E Application Guide for ENOS 8 4 ...
Страница 70: ...70 NE2552E Application Guide for ENOS 8 4 ...
Страница 85: ... Copyright Lenovo 2018 85 Part 2 Securing the Switch ...
Страница 86: ...86 NE2552E Application Guide for ENOS 8 4 ...
Страница 112: ...112 NE2552E Application Guide for ENOS 8 4 ...
Страница 134: ...134 NE2552E Application Guide for ENOS 8 4 ...
Страница 154: ...154 NE2552E Application Guide for ENOS 8 4 ...
Страница 194: ...194 NE2552E Application Guide for ENOS 8 4 ...
Страница 218: ...218 NE2552E Application Guide for ENOS 8 4 ...
Страница 234: ...234 NE2552E Application Guide for ENOS 8 4 ...
Страница 238: ...238 NE2552E Application Guide for ENOS 8 4 ...
Страница 239: ... Copyright Lenovo 2018 239 Part 4 Advanced Switching Features ...
Страница 240: ...240 NE2552E Application Guide for ENOS 8 4 ...
Страница 242: ...242 NE2552E Application Guide for ENOS 8 4 ...
Страница 278: ...278 NE2552E Application Guide for ENOS 8 4 ...
Страница 284: ...284 NE2552E Application Guide for ENOS 8 4 ...
Страница 314: ...314 NE2552E Application Guide for ENOS 8 4 ...
Страница 338: ...338 NE2552E Application Guide for ENOS 8 4 ...
Страница 374: ...374 NE2552E Application Guide for ENOS 8 4 ...
Страница 388: ...388 NE2552E Application Guide for ENOS 8 4 ...
Страница 418: ...418 NE2552E Application Guide for ENOS 8 4 ...
Страница 430: ...430 NE2552E Application Guide for ENOS 8 4 ...
Страница 432: ...432 NE2552E Application Guide for ENOS 8 4 ...
Страница 436: ...436 NE2552E Application Guide for ENOS 8 4 ...
Страница 460: ...460 NE2552E Application Guide for ENOS 8 4 ...
Страница 461: ... Copyright Lenovo 2018 461 Part 7 Network Management ...
Страница 462: ...462 NE2552E Application Guide for ENOS 8 4 ...
Страница 476: ...476 NE2552E Application Guide for ENOS 8 4 ...
Страница 498: ...498 NE2552E Application Guide for ENOS 8 4 ...
Страница 520: ...520 NE2552E Application Guide for ENOS 8 4 ...
Страница 534: ...534 NE2552E Application Guide for ENOS 8 4 ...
Страница 536: ...536 NE2552E Application Guide for ENOS 8 4 ...
Страница 544: ...544 NE2552E Application Guide for ENOS 8 4 ...
Страница 549: ... Copyright Lenovo 2018 549 Part 9 Appendices ...
Страница 550: ...550 NE2552E Application Guide for ENOS 8 4 ...
Страница 566: ...566 NE2552E Application Guide for ENOS 8 4 ...
Страница 572: ...572 NE2552E Application Guide for ENOS 8 4 ...
Страница 573: ......
Страница 574: ...Part Number 01KN246 Printed in USA IP P N 01KN246 ...