342
NE2552E Application Guide for ENOS 8.4
Setting up Authentication
Before
you
can
use
IPsec,
you
need
to
have
key
policy
authentication
in
place.
There
are
two
types
of
key
policy
authentication:
Preshared
key
(default)
The
parties
agree
on
a
shared,
secret
key
that
is
used
for
authentication
in
an
IPsec
policy.
During
security
negotiation,
information
is
encrypted
before
transmission
by
using
a
session
key
created
by
using
a
Diffie
‐
Hellman
calculation
and
the
shared,
secret
key.
Information
is
decrypted
on
the
receiving
end
using
the
same
key.
One
IPsec
peer
authenticates
the
other
peer
ʹ
s
packet
by
decryption
and
verification
of
the
hash
inside
the
packet
(the
hash
inside
the
packet
is
a
hash
of
the
preshared
key).
If
authentication
fails,
the
packet
is
discarded.
Digital
certificate
(using
RSA
algorithms)
The
peer
being
validated
must
hold
a
digital
certificate
signed
by
a
trusted
Certificate
Authority
and
the
private
key
for
that
digital
certificate.
The
side
performing
the
authentication
only
needs
a
copy
of
the
trusted
certificate
authorities
digital
certificate.
During
IKEv2
authentication,
the
side
being
validated
sends
a
copy
of
the
digital
certificate
and
a
hash
value
signed
using
the
private
key.
The
certificate
can
be
either
generated
or
imported.
Note:
During
the
IKEv2
negotiation
phase,
the
digital
certificate
takes
precedence
over
the
preshared
key.
Creating an IKEv2 Proposal
With
IKEv2,
a
single
policy
can
have
multiple
encryption
and
authentication
types,
as
well
as
multiple
integrity
algorithms.
To
create
an
IKEv2
proposal:
1.
Enter
IKEv2
proposal
mode.
2.
Set
the
DES
encryption
algorithm.
3.
Set
the
authentication
integrity
algorithm
type.
4.
Set
the
Diffie
‐
Hellman
group.
NE2552E(config)#
ikev2 proposal
NE2552E(config-ikev2-prop)#
encryption aes-cbc
NE2552E(config-ikev2-prop)#
integrity sha1
NE2552E(config-ikev2-prop)#
group 24
Содержание ThinkSystem NE2552E
Страница 27: ... Copyright Lenovo 2018 27 Part 1 Getting Started ...
Страница 28: ...28 NE2552E Application Guide for ENOS 8 4 ...
Страница 70: ...70 NE2552E Application Guide for ENOS 8 4 ...
Страница 85: ... Copyright Lenovo 2018 85 Part 2 Securing the Switch ...
Страница 86: ...86 NE2552E Application Guide for ENOS 8 4 ...
Страница 112: ...112 NE2552E Application Guide for ENOS 8 4 ...
Страница 134: ...134 NE2552E Application Guide for ENOS 8 4 ...
Страница 154: ...154 NE2552E Application Guide for ENOS 8 4 ...
Страница 194: ...194 NE2552E Application Guide for ENOS 8 4 ...
Страница 218: ...218 NE2552E Application Guide for ENOS 8 4 ...
Страница 234: ...234 NE2552E Application Guide for ENOS 8 4 ...
Страница 238: ...238 NE2552E Application Guide for ENOS 8 4 ...
Страница 239: ... Copyright Lenovo 2018 239 Part 4 Advanced Switching Features ...
Страница 240: ...240 NE2552E Application Guide for ENOS 8 4 ...
Страница 242: ...242 NE2552E Application Guide for ENOS 8 4 ...
Страница 278: ...278 NE2552E Application Guide for ENOS 8 4 ...
Страница 284: ...284 NE2552E Application Guide for ENOS 8 4 ...
Страница 314: ...314 NE2552E Application Guide for ENOS 8 4 ...
Страница 338: ...338 NE2552E Application Guide for ENOS 8 4 ...
Страница 374: ...374 NE2552E Application Guide for ENOS 8 4 ...
Страница 388: ...388 NE2552E Application Guide for ENOS 8 4 ...
Страница 418: ...418 NE2552E Application Guide for ENOS 8 4 ...
Страница 430: ...430 NE2552E Application Guide for ENOS 8 4 ...
Страница 432: ...432 NE2552E Application Guide for ENOS 8 4 ...
Страница 436: ...436 NE2552E Application Guide for ENOS 8 4 ...
Страница 460: ...460 NE2552E Application Guide for ENOS 8 4 ...
Страница 461: ... Copyright Lenovo 2018 461 Part 7 Network Management ...
Страница 462: ...462 NE2552E Application Guide for ENOS 8 4 ...
Страница 476: ...476 NE2552E Application Guide for ENOS 8 4 ...
Страница 498: ...498 NE2552E Application Guide for ENOS 8 4 ...
Страница 520: ...520 NE2552E Application Guide for ENOS 8 4 ...
Страница 534: ...534 NE2552E Application Guide for ENOS 8 4 ...
Страница 536: ...536 NE2552E Application Guide for ENOS 8 4 ...
Страница 544: ...544 NE2552E Application Guide for ENOS 8 4 ...
Страница 549: ... Copyright Lenovo 2018 549 Part 9 Appendices ...
Страница 550: ...550 NE2552E Application Guide for ENOS 8 4 ...
Страница 566: ...566 NE2552E Application Guide for ENOS 8 4 ...
Страница 572: ...572 NE2552E Application Guide for ENOS 8 4 ...
Страница 573: ......
Страница 574: ...Part Number 01KN246 Printed in USA IP P N 01KN246 ...