
Chapter 13 Introduction to IPSec
P-2802H(W)(L)-I Series User’s Guide
182
Figure 105
Transport and Tunnel Mode IPSec Encapsulation
13.3.1 Transport Mode
Transport
mode is used to protect upper layer protocols and only affects the data in the IP
packet. In
Transport
mode, the IP packet contains the security protocol (
AH
or
ESP
) located
after the original IP header and options, but before any upper layer protocols contained in the
packet (such as TCP and UDP).
With
ESP,
protection is applied only to the upper layer protocols contained in the packet. The
IP header information and options are not used in the authentication process. Therefore, the
originating IP address cannot be verified for integrity against the data.
With the use of
AH
as the security protocol, protection is extended forward into the IP header
to verify the integrity of the entire packet by use of portions of the original IP header in the
hashing process.
13.3.2 Tunnel Mode
Tunnel
mode encapsulates the entire IP packet to transmit it securely. A
Tunnel
mode is
required for gateway services to provide access to internal systems.
Tunnel
mode is
fundamentally an IP tunnel with authentication and encryption. This is the most common
mode of operation.
Tunnel
mode is required for gateway to gateway and host to gateway
communications.
Tunnel
mode communications have two sets of IP headers:
•
Outside header
: The outside IP header contains the destination IP address of the VPN
gateway.
•
Inside header
: The inside IP header contains the destination IP address of the final system
behind the VPN gateway. The security protocol appears after the outer IP header and
before the inside IP header.
13.4 IPSec and NAT
Read this section if you are running IPSec on a host computer behind the ZyXEL Device.
NAT is incompatible with the
AH
protocol in both
Transport
and
Tunnel
mode. An IPSec
VPN using the
AH
protocol digitally signs the outbound packet, both data payload and
headers, with a hash value appended to the packet. When using
AH
protocol, packet contents
(the data payload) are not encrypted.
Содержание P-2802H-I Series
Страница 1: ...www zyxel com P 2802H W L I Series VDSL VoIP IAD User s Guide Version 3 70 6 2007 Edition 1...
Страница 2: ......
Страница 7: ...Safety Warnings P 2802H W L I Series User s Guide 7...
Страница 8: ...Safety Warnings P 2802H W L I Series User s Guide 8...
Страница 10: ...Contents Overview P 2802H W L I Series User s Guide 10...
Страница 32: ...List of Tables P 2802H W L I Series User s Guide 32...
Страница 33: ...33 PART I Introduction Introducing the ZyXEL Device 35 Introducing the Web Configurator 43...
Страница 34: ...34...
Страница 50: ...Chapter 2 Introducing the Web Configurator P 2802H W L I Series User s Guide 50...
Страница 51: ...51 PART II Wizard Internet and Wireless Setup Wizard 53 VoIP Wizard And Example 65...
Страница 52: ...52...
Страница 64: ...Chapter 3 Internet and Wireless Setup Wizard P 2802H W L I Series User s Guide 64...
Страница 70: ...Chapter 4 VoIP Wizard And Example P 2802H W L I Series User s Guide 70...
Страница 72: ...72...
Страница 82: ...Chapter 5 Status Screens P 2802H W L I Series User s Guide 82...
Страница 88: ...Chapter 6 WAN Setup P 2802H W L I Series User s Guide 88...
Страница 116: ...Chapter 8 Wireless LAN P 2802H W L I Series User s Guide 116...
Страница 154: ...Chapter 10 Voice P 2802H W L I Series User s Guide 154...
Страница 174: ...Chapter 11 Firewalls P 2802H W L I Series User s Guide 174...
Страница 178: ...Chapter 12 Content Filtering P 2802H W L I Series User s Guide 178...
Страница 184: ...Chapter 13 Introduction to IPSec P 2802H W L I Series User s Guide 184...
Страница 219: ...Chapter 15 Certificates P 2802H W L I Series User s Guide 219 Figure 122 My Certificate Details...
Страница 238: ...Chapter 16 Static Route P 2802H W L I Series User s Guide 238...
Страница 250: ...Chapter 17 Quality of Service QoS P 2802H W L I Series User s Guide 250...
Страница 254: ...Chapter 18 Dynamic DNS Setup P 2802H W L I Series User s Guide 254...
Страница 282: ...Chapter 20 Universal Plug and Play UPnP P 2802H W L I Series User s Guide 282...
Страница 284: ...284...
Страница 324: ...Chapter 25 Troubleshooting P 2802H W L I Series User s Guide 324...
Страница 334: ...Chapter 26 Product Specifications P 2802H W L I Series User s Guide 334...
Страница 336: ...336...
Страница 348: ...Appendix A Setting up Your Computer s IP Address P 2802H W L I Series User s Guide 348...
Страница 404: ...Appendix G Legal Information P 2802H W L I Series User s Guide 404...
Страница 410: ...Appendix H Customer Support P 2802H W L I Series User s Guide 410...
Страница 418: ...Index P 2802H W L I Series User s Guide 418...