Internet Key Exchange for VPNs 6-1
Chapter 6
Internet Key Exchange for VPNs
IPsec
stands for IP Security, a set of protocols that suppor ts secure exchange of IP packets at the IP layer.
IPsec is deployed widely to implement Vir tual Private Networks (VPNs). See
“Virtual Private Networks (VPNs)”
on page 5-1
for more information.
The Motorola Netopia® Embedded Software Version 8.7.4 suppor ts Internet Key Exchange (IKE) for secure
encr ypted communication over a VPN tunnel.
This chapter covers the following topics:
•
“Overview” on page 6-1
•
“Internet Key Exchange (IKE) Configuration” on page 6-2
•
“Key Management” on page 6-11
•
“IPsec WAN Configuration Screens” on page 6-21
•
“IPsec Manual Key Entry” on page 6-22
Overview
IPsec suppor ts two encapsulation modes: Transpor t and Tunnel. Transpor t mode encr ypts only the data por tion
(payload) of each packet, but leaves the header untouched. Tunnel mode encr ypts both the header and the
payload. On the receiving side, an IPsec-compliant device decr ypts each packet. Motorola Netopia
®
Routers
suppor t Tunnel mode.
DES
stands for Data Encr yption Standard, a popular symmetric-key encr yption method. DES uses a 56-bit key.
Motorola Netopia
®
Routers offer IPsec 3DES (triple DES) encr yption as a standard option.
Internet Key Exchange (IKE)
is an authentication and encr yption key management protocol used in conjunction
with the IPsec standard.
IKE is a two-phase protocol for key exchange.
•
Phase 1 authenticates the security gateways and establishes the
Security Parameters
(SPs) they will use
to negotiate on behalf of the clients.
Security Associations
(SAs) are sets of information values that allow
the two devices on the Internet to communicate securely.
•
Phase 2 establishes the tunnel and provides for secure transpor t of data.
IPsec can be configured without IKE, but IKE offers additional features, flexibility, and ease of configuration. Key
exchange between your local Router and a remote point can be configured either manually or by using the key
exchange protocol.
Содержание Netopia Embedded Software
Страница 1: ...Administrator s Handbook Motorola Netopia Embedded Seftware Version 8 7 4 Enterprise Series Routers ...
Страница 10: ...x Administrator s Handbook ...
Страница 16: ...1 6 Administrator s Handbook ...
Страница 44: ...2 28 Administrator s Handbook ...
Страница 108: ...3 64 Administrator s Handbook ...
Страница 176: ...5 34 Administrator s Handbook ...
Страница 202: ...6 26 Administrator s Handbook ...
Страница 243: ...IP Setup 7 41 Additional LAN Configuration Name IP Address Additional LAN 1 1 1 1 1 Additional LAN 2 0 0 0 0 ...
Страница 244: ...7 42 Administrator s Handbook ...
Страница 340: ...Index 6 ...