UTT Technologies
Chapter 10 VPN
http://www.uttglobal.com
Page
13813813
original IP header cannot be authenticated.
Figure 11-13 Transport Mode
9.5.1.3 Key Management
The term
key management
refers to the creation, distribution, storage and deletion of
keys. Key management is a critical part of IPSec. IPSec uses cryptographic keys for
authentication and encryption. On the UTT VPN gateway, IPSec supports both manual
and automatic key management.
1. Manual Key
With manual key management, all the security parameters at both endpoints of an IPSec
tunnel are configured manually. In general, there are more than 20 parameters that need
to be configured at each endpoint.
Manual key management is feasible for small VPN networks (such as, a network with a
few VPN appliances) where the distribution, maintenance and tracking of keys are not
difficult. However, for large VPN networks with a large number of VPN appliances across
great distances, this method is often unreliable or infeasible. When a key is initially
distributed, there may be no way to verify that the key has not been compromised during
transmission. In addition, whenever you want to change the keys, you need redistribute
the new keys to all the VPN appliances; and this causes the same security issues as
when the key was initially distributed. In conclusion, manual key management is only
suitable
for
relatively
small
VPN
networks.