Reference Manual for the ProSafe VPN Firewall FVS114
Virtual Private Networking
C-9
202-10098-01, April 2005
Figure C-5: VPN tunnel Security Associaton (SA)
The SA contains all the information necessary for gateway A to negotiate a secure and encrypted
communication stream with gateway B. This communication is often referred to as a “tunnel.” The
gateways contain this information so that it does not have to be loaded onto every computer
connected to the gateways.
Each gateway must negotiate its SA with another gateway using the parameters and processes
established by IPSec. As illustrated below, the most common method of accomplishing this
process is via the Internet Key Exchange (IKE) protocol which automates some of the negotiation
procedures.
Figure C-6: IPSec Security Association (SA) negotiation
Or, you can configure your gateways using manual key exchange, which involves manually
configuring each paramter on both gateways.
1.
The IPSec software on Host A initiates the IPSec process in an attempt to communicate
with Host B.
The two computers then begin the Internet Key Exchange (IKE) process.
VPN Gateway A
VPN Gateway B
VPN Tunnel
PCs
PCs
VPN Gateway
VPN Gateway
1) Communication
request sent to VPN Gateway
2) IKE Phase I authentication
3) IKE Phase II negotiation
4) Secure data transfer
5) IPSec tunnel termination
IPSec Security Association IKE
VPN Tunnel Negotiation Steps
Содержание FVS114NA
Страница 4: ...202 10098 01 April 2005 iv...
Страница 12: ...202 10098 01 April 2005 xii Contents...
Страница 16: ...Reference Manual for the ProSafe VPN Firewall FVS114 1 4 About This Manual 202 10098 01 April 2005...
Страница 116: ...Reference Manual for the ProSafe VPN Firewall FVS114 6 28 Advanced Virtual Private Networking 202 10098 01 April 2005...
Страница 148: ...Reference Manual for the ProSafe VPN Firewall FVS114 9 8 Troubleshooting 202 10098 01 April 2005...
Страница 166: ...Reference Manual for the ProSafe VPN Firewall FVS114 B 16 Network Routing and Firewall Basics 202 10098 01 April 2005...
Страница 200: ...Reference Manual for the ProSafe VPN Firewall FVS114 D 22 Preparing Your Network 202 10098 01 April 2005...
Страница 211: ...Reference Manual for the ProSafe VPN Firewall FVS114 Glossary 11 202 10098 01 April 2005...
Страница 212: ...Reference Manual for the ProSafe VPN Firewall FVS114 12 Glossary 202 10098 01 April 2005...