C
Appendix C
About VPNs
Overview
A VPN (Virtual Private Network) provides a secure connection between 2 points, over
an insecure network - typically the Internet. This secure connection is called a
VPN
Tunnel
.
There are many standards and protocols for VPNs. The standard implemented in the
ADE-4300/ADW-4300 is
IPSec
.
IPSec
IPSec is a near-ubiquitous VPN security standard, designed for use with TCP/IP
networks. It works at the packet level, and authenticates and encrypts all packets
traveling over the VPN Tunnel. Thus, it does not matter what applications are used on
your PC. Any application can use the VPN like any other network connection.
IPsec VPNs exchange information through logical connections called
SA
s (Security
Associations). An SA is simply a definition of the protocols, algorithms and keys used
between the two VPN devices (endpoints).
Each IPsec VPN has two SAs - one in each direction. If
IKE
(Internet Key Exchange)
is used to generate and exchange keys, there are also SA's for the IKE connection as
well as the IPsec connection.
There are two security modes possible with IPSec:
•
Transport Mode
- the payload (data) part of the packet is encapsulated through
encryption but the IP header remains in the clear (unchanged).
The ADE-4300/ADW-4300 does NOT support Transport Mode.
•
Tunnel Mode
- everything is encapsulated, including the original IP header, and a
new IP header is generated. Only the new header in the clear (i.e. not protected).
This system provides enhanced security.
The ADE-4300/ADW-4300 always uses Tunnel Mode.
IKE
IKE (Internet Key Exchange) is an optional, but widely used, component of IPsec. IKE
provides a method of negotiating and generating the keys and IDs required by IPSec.
If using IKE, only a single key is required to be provided during configuration. Also,
IKE supports using
Certificates
(provided by CAs - Certification Authorities) to
authenticate the identify of the remote user or gateway.
If IKE is NOT used, then all keys and IDs (SPIs) must be entered manually, and
Certificates can NOT be used. This is called a "Manual Key Exchange".
When using IKE, there are 2 phases to creating the VPN tunnel:
•
Phase I
is the negotiation and establishment up of the IKE connection.
•
Phase II
is the negotiation and establishment up of the IPsec connection.
128
Содержание ADE-4300A
Страница 1: ...ADSL 2 2 VPN Firewall Router ADE 4300A B ADW 4300A B User s Manual...
Страница 57: ...ADE 4300 ADW 4300 User Guide 52...
Страница 60: ...Operation and Status 55...