CHAPTER 11: Using Virtual Private Networks (VPN)
306
Vcontroller
Three major qualifications are established in an IPSec
action:
Mode
Tunnel
mode is used when Firebox Vclass
appliances act as security gateways on both ends or
when a remote Firebox Vclass VPN client connects
to a Firebox Vclass security appliance. Data packets
are encrypted and sent from one appliance to the
other, where decryption takes place and the data is
forwarded to its final destination. You must specify
the IP address of each tunnel peer.
Transport
mode is usually applied in end-to-end
secured communications.
Key Management
This specifies whether the key is created
automatically or manually. Automatic key
management is done in accordance with IKE, an
IETF standard protocol. Using IKE, encryption
keys are automatically negotiated and selected by
two connected security appliances. This provides
the easiest, most efficient wat to manage keys.
Encryption/authentication
Two principal types of security protocols protect
data packets in Internet communications. The AH
(Authentication Header) protocol is applied to IP
packets for authentication, while ESP
(Encapsulating Security Payload) can be applied to
IP packets for both encryption and authentication.
Using Authentication and Encryption
The Firebox Vclass security appliance supports the follow-
ing algorithms:
Authentication Header (AH)
MD5, SHA
Encapsulating Security Payload (ESP)
DES, 3DES
Содержание Firebox V10
Страница 1: ...WatchGuard Firebox Vclass User Guide Vcontroller 5 0 ...
Страница 32: ...xxxii Vcontroller ...
Страница 40: ...CHAPTER 1 Introduction 8 Vcontroller ...
Страница 52: ...CHAPTER 2 Service and Support 20 Vcontroller ...
Страница 70: ...CHAPTER 3 Getting Started 38 Vcontroller ...
Страница 110: ...CHAPTER 4 Firebox Vclass Basics 78 Vcontroller ...
Страница 120: ...CHAPTER 5 Router and Transparent Mode 88 Vcontroller Configure the Interfaces in Transparent Mode on page 45 ...
Страница 140: ...CHAPTER 6 System Configuration 108 Vcontroller 2 To configure a static route click Add The Add Route dialog box appears ...
Страница 190: ...CHAPTER 7 Using Account Manager 158 Vcontroller ...
Страница 268: ...CHAPTER 9 Security Policy Examples 236 Vcontroller ...
Страница 410: ...CHAPTER 14 Monitoring the Firebox Vclass 378 Vcontroller ...
Страница 456: ...CHAPTER 18 Using the Diagnostics CLI Feature 424 Vcontroller ...